A03: digest-pin actions/* steps in all workflows #12

Closed
opened 2026-08-13 09:35:03 +00:00 by nalum · 0 comments
Owner

The house rule says third-party actions are digest-pinned, and golangci/buf/docker actions comply — but the actions/* steps do not: actions/checkout@v4, setup-go@v5, setup-node@v4, setup-java@v4, cache@v3, upload/download-artifact@v3 across all four .gitea/workflows/*.yml.

From a Forgejo runner, everything on github.com is third-party. A moved v4 tag silently changes what runs — including in the release.yml signing jobs where COSIGN_PRIVATE_KEY sits in the step environment.

Fix: pin each actions/* reference to a commit digest, with the tag in a comment for humans.


Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

The house rule says third-party actions are digest-pinned, and golangci/buf/docker actions comply — but the `actions/*` steps do not: `actions/checkout@v4`, `setup-go@v5`, `setup-node@v4`, `setup-java@v4`, `cache@v3`, `upload/download-artifact@v3` across all four `.gitea/workflows/*.yml`. From a Forgejo runner, everything on github.com is third-party. A moved `v4` tag silently changes what runs — including in the `release.yml` signing jobs where `COSIGN_PRIVATE_KEY` sits in the step environment. **Fix**: pin each `actions/*` reference to a commit digest, with the tag in a comment for humans. --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:47 +00:00
nalum closed this issue 2026-08-13 11:39:26 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#12
No description provided.