Skip to content

fix: pin all GitHub Actions to commit SHAs - #93

Merged
gtrivedi88 merged 1 commit into
eclipse-che:mainfrom
gtrivedi88:fix/pin-github-actions-to-shas
Sep 2, 2026
Merged

gtrivedi88 merged 1 commit into
eclipse-che:mainfrom
gtrivedi88:fix/pin-github-actions-to-shas

Conversation

@gtrivedi88

Copy link
Copy Markdown
Contributor

Summary

Pin every GitHub Actions reference to an immutable commit SHA to mitigate supply chain attacks like the tj-actions/changed-files compromise (CVE-2025-30066).

Changes across 5 workflow files:

SHA pinning (25 action references):

Action Old ref New pinned ref
actions/checkout @v4 SHA # v4
actions/upload-artifact @v4 SHA # v4
actions/setup-node @v4 SHA # v4
actions/github-script @v7 SHA # v7
ruby/setup-ruby @v1 SHA # v1
docker/setup-qemu-action @v3 SHA # v3
docker/setup-buildx-action @v3 SHA # v3
docker/login-action @v3 SHA # v3
limjh16/jekyll-action-ts @v2 SHA # v2
peaceiris/actions-gh-pages @v4 SHA # v4
dawidd6/action-download-artifact @v9 SHA # v9

Additional security fixes:

  1. Replaced jitterbit/get-changed-files@v1 — This action is abandoned (last commit May 2021) and uses the same mutable-tag attack vector as tj-actions. Replaced with a gh api call that fetches changed files directly from the GitHub API.

  2. Replaced benoitf/vale-action@reviewdog — The reviewdog branch does not exist on the benoitf fork (returns 404). Switched to the upstream errata-ai/vale-action pinned to the current reviewdog branch SHA.

Ref: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/273

Test plan

  • CI workflows pass on this PR
  • Verify the gh api replacement for changed-files works on PR events
  • Verify vale linting works with the upstream errata-ai/vale-action

Made with Cursor

Mitigate supply chain attacks (CVE-2025-30066) by pinning every
action reference to an immutable commit SHA instead of mutable
version tags or branch names.

Also:
- Replace abandoned jitterbit/get-changed-files with gh API call
- Replace broken benoitf/vale-action@reviewdog with upstream errata-ai/vale-action

Ref: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/273
Co-authored-by: Cursor <cursoragent@cursor.com>
@gtrivedi88
gtrivedi88 merged commit 89a6170 into eclipse-che:main Sep 2, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants