Skip to content

security: pin GitHub Actions to SHAs, scope workflow permissions, enable Dependabot - #4

Merged
JRemitz merged 2 commits into
mainfrom
security/pin-actions-and-scope-permissions
Sep 4, 2026
Merged

JRemitz merged 2 commits into
mainfrom
security/pin-actions-and-scope-permissions

Conversation

@JRemitz

@JRemitz JRemitz commented Jun 8, 2026

Copy link
Copy Markdown
Contributor

Summary

Propagates the security hardening from StreamnDad/reeln-cli#29 to this repo.

  • Pin every third-party GitHub Action to a full commit SHA with a # vX.Y.Z comment. Defeats tag-mutation supply-chain attacks (highest-risk action being any that runs with id-token: write).
  • Add explicit job-level permissions: contents: read so GITHUB_TOKEN is scoped to the minimum needed. Jobs that need write scopes keep them alongside.
  • Add .github/dependabot.yml so Dependabot opens weekly grouped dependency PRs across every ecosystem this repo uses. Pairs with enabling Dependabot security updates at the repo level (done out-of-band via API).
  • Refresh lockfile (if applicable) so any transitive CVE-fix releases land immediately.

Test plan

  • CI green on this branch
  • No behavioural changes to workflow logic, matrix, or step ordering
  • Spot-check that resolved SHAs match the tag comments (e.g. actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 is v4.3.1)

🤖 Generated with Claude Code

JRemitz and others added 2 commits June 9, 2026 07:54
- Pin every third-party Action to a full 40-char commit SHA with a
  # vX.Y.Z comment, defeating tag-mutation supply-chain attacks. Mirrors
  StreamnDad/reeln-cli#29.
- Add explicit job-level `permissions: contents: read` so GITHUB_TOKEN
  is least-privileged. Jobs that need write scopes keep them alongside.
- Add .github/dependabot.yml so Dependabot opens weekly grouped
  dependency PRs going forward, and is positioned to file security
  updates the moment they're published.

Co-Authored-By: Claude <noreply@anthropic.com>
`cargo update` within existing semver constraints. Picks up patch/minor
releases that close known advisories without touching Cargo.toml.

Co-Authored-By: Claude <noreply@anthropic.com>
@JRemitz
JRemitz force-pushed the security/pin-actions-and-scope-permissions branch from 10a278a to ad87221 Compare June 9, 2026 12:54
@JRemitz JRemitz self-assigned this Sep 4, 2026
@JRemitz
JRemitz merged commit 6562425 into main Sep 4, 2026
6 checks passed
@JRemitz
JRemitz deleted the security/pin-actions-and-scope-permissions branch September 4, 2026 22:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant