Security: harden CI workflows and composite actions - #43
Merged
Merged
Conversation
- Pin all third-party and GitHub actions to commit SHAs (tag kept as
comment); several of them receive PAT_TOKEN, AUR_SSH_PRIVATE_KEY and
WINGET_PUBLISH_TOKEN.
- Pass inputs, event payload values and step outputs via env instead of
inline ${{ }} expansion in run scripts (script injection), notably the
PR-controlled release version in version-guard and the commit message
and SSH key in the AUR fallback.
- Validate the version from the repository_dispatch payload.
- AUR fallback: write the key with umask 077, StrictHostKeyChecking
accept-new instead of no.
- Pin appimagetool to 1.9.1 and verify its SHA-256 before executing it.
- Default the GITHUB_TOKEN to contents: read where no permissions were set.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XSUJwZ17AWMdDvYXboJAbQ
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Hardens the pipelines against supply-chain attacks and script injection.
uses:now reference a commit SHA, with the tag kept as a comment for Dependabot/Renovate. This matters most for Actions that receive secrets:rickstaa/action-create-taggetsPAT_TOKENKSXGitHub/github-actions-deploy-aurgetsAUR_SSH_PRIVATE_KEYvedantmgoyal9/winget-releaser@maingetsWINGET_PUBLISH_TOKENpeter-evans/repository-dispatchgetsPAT_TOKENenvinstead of inline${{ }}inrun:blocks:version-guard.yml:release_versioncomes from the csproj of the PR branch, and the part after-is not validated. It used to be inserted into bash and into Python source. It is now passed viaenvandos.environ.deploy-aur: commit message, package name, flags and the SSH key are now passed viaenv. The key is written withumask 077.deploy-release.yml:client_payload.versionis passed viaenvand validated againstX.Y.Z.build-and-package.yml,build-appimage,determine-version: inputs are passed viaenv.appimagetoolwas downloaded from the rollingcontinuoustag without any integrity check and then executed. It is now pinned to1.9.1, which is the same commit ascontinuoustoday, and its SHA-256 is checked withsha256sum --check --strict.permissions: contents: readadded totest.yml,version-guard.yml,staging.ymlandbuild-and-package.yml(a reusable workflow can only reduce permissions).StrictHostKeyChecking nochanged toaccept-new. See the reviewer questions.Changes Made
Testing Performed
Test Evidence
actionlint1.7.7 reports no new findings. The only remaining one is the unknown runner labelubuntu-slim, which exists ondevelopmenttoo and is unknown to that actionlint version.run:block contains an inline${{ }}any more, and every script passesbash -n.sha256sum --check --strictline was tested with the correct and with a wrong hash (exit code 0 and 1).git ls-remote; for annotated tags, the commit SHA (^{}) is used.Checklist
dotnet build,dotnet test) (no .NET changes)Questions for Reviewers
accept-newis the same asnoon a fresh runner. Real protection requires putting the published AUR host keys (ED25519/ECDSA/RSA) intoknown_hostsand usingStrictHostKeyChecking yes. aur.archlinux.org was not reachable from the build environment, so the keys could not be verified and were not pinned.vedantmgoyal9/winget-releaseris pinned to the currentmaincommit. There is no release tag for it.Notes for Reviewers:
🤖 Generated with Claude Code
https://claude.ai/code/session_01XSUJwZ17AWMdDvYXboJAbQ
Generated by Claude Code