AOSSIE-Org / AOSSIE-Org/Template-Repo

Pin GitHub Actions to commit SHAs for supply chain security

Aperta
#75 0 commenti 0 reazioni 1 assegnatario Rivendicata da @kpj2006 Vedi su GitHub
Lingua principale
YAML
Stelle
17
Fork
29
Merge medio
3g 13h
PR unite (30g)
6

Descrizione

## Description

Currently, most workflows in this repository use floating major-version tags for GitHub Actions (e.g., `actions/checkout@v4`, `actions/setup-node@v3`). While convenient, this approach poses a supply chain security risk: a tag can be force-pushed by the action author (or a compromised account), potentially introducing malicious code into our CI/CD pipelines.

## Proposed Solution

Pin all GitHub Action references to their full commit SHAs with inline comments indicating the version:

```yaml
# Instead of:
uses: actions/checkout@v4

# Use:
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.2.2
```

## Benefits

- **Immutability**: Commit SHAs cannot be altered, ensuring the exact code is executed
- **Transparency**: Version comments maintain readability
- **Security**: Eliminates risk of tag-based supply chain attacks

## Scope

This affects multiple workflow files in `.github/workflows/`:
- `template-sync.yml`
- And other workflow files across the repository

## References

- Related discussion: https://github.com/AOSSIE-Org/Template-Repo/pull/74#discussion_r2835914445
- Requested by: @kpj2006

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.