AOSSIE-Org / AOSSIE-Org/Template-Repo

Pin GitHub Actions to commit SHAs for supply chain security

Abierto
#75 0 comentarios 0 reacciones 1 asignado Reclamado por @kpj2006 Ver en GitHub
Lenguaje dominante
YAML
Estrellas
17
Forks
29
Merge medio
3 d 13 h
PR fusionados (30 d)
6

Descripción

## Description

Currently, most workflows in this repository use floating major-version tags for GitHub Actions (e.g., `actions/checkout@v4`, `actions/setup-node@v3`). While convenient, this approach poses a supply chain security risk: a tag can be force-pushed by the action author (or a compromised account), potentially introducing malicious code into our CI/CD pipelines.

## Proposed Solution

Pin all GitHub Action references to their full commit SHAs with inline comments indicating the version:

```yaml
# Instead of:
uses: actions/checkout@v4

# Use:
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.2.2
```

## Benefits

- **Immutability**: Commit SHAs cannot be altered, ensuring the exact code is executed
- **Transparency**: Version comments maintain readability
- **Security**: Eliminates risk of tag-based supply chain attacks

## Scope

This affects multiple workflow files in `.github/workflows/`:
- `template-sync.yml`
- And other workflow files across the repository

## References

- Related discussion: https://github.com/AOSSIE-Org/Template-Repo/pull/74#discussion_r2835914445
- Requested by: @kpj2006

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.