Skip to content

[MEDIUM] Pin workflow actions to immutable commits - #263

Open
OskarEichler wants to merge 1 commit into
heartcombo:mainfrom
OskarEichler:codex/security-pin-actions
Open

OskarEichler wants to merge 1 commit into
heartcombo:mainfrom
OskarEichler:codex/security-pin-actions

Conversation

@OskarEichler

Copy link
Copy Markdown

Summary

  • Pin every GitHub Actions dependency to an immutable commit.
  • Preserve the currently selected action versions in comments.
  • Cover the privileged RubyGems release workflow as well as test and RuboCop workflows.

Security impact

The release job grants contents: write and id-token: write. Resolving an action through a mutable tag lets a compromised or retargeted tag execute with those permissions and affect package publishing. Immutable commit references make the reviewed action code the code that runs.

The read-only CI jobs are pinned at the same boundary to prevent unreviewed action changes from entering those jobs.

Verification

  • rbenv exec bundle exec rake: 116 runs, 291 assertions, 0 failures
  • rbenv exec bundle exec rubocop: 22 files, no offenses
  • rbenv exec bundle exec rake build: built responders-3.2.1.gem
  • Parsed all workflow YAML files with Ruby
  • Confirmed all 7 uses: references use 40-character commit SHAs
  • git diff --check

Limitations

The RubyGems trusted-publishing/OIDC release itself was not exercised locally; this change only replaces action references and preserves workflow inputs and permissions.

Breaking changes

None. Runtime code, dependencies, workflow behavior, and selected action versions are unchanged.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant