ci: pin actions by digest and verify tool downloads #28
No reviewers
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app!28
Loading…
Reference in a new issue
No description provided.
Delete branch "ci/pin-actions-and-tools"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Two supply-chain gaps in
.gitea/workflows/:Digest-pin
actions/*— everyactions/checkout@v4-style tag pin becomes a full-commit-SHA pin with the exact version in a comment (checkout v4.4.0, setup-go v5.6.0, setup-node v4.4.0, setup-java v4.9.1, cache v3.5.0, upload-artifact v3.2.2, download-artifact v3.1.0). From a Forgejo runner everything on github.com is third-party; a moved tag silently changes what runs — including the signing jobs holdingCOSIGN_PRIVATE_KEY. Fixes #12Checksum-verify fetched binaries — cosign, timoni, flux, Android cmdline-tools, and protoc downloads now verify a hard-coded sha256 before use (11 verification lines). cosign/timoni/flux hashes cross-checked against the projects' official checksum files; Google/protobuf publish none, so those were computed from two independent TLS downloads. Piped
curl | tarinstalls restructured to download → verify → extract. No tool versions changed. Fixes #13The legacy
.github/workflows/directory is untouched.🤖 Generated with Claude Code
bc23e6d2dba805eb451f