ci: pin actions by digest and verify tool downloads #28

Merged
nalum merged 1 commit from ci/pin-actions-and-tools into main 2026-08-13 11:39:26 +00:00
Owner

Two supply-chain gaps in .gitea/workflows/:

Digest-pin actions/* — every actions/checkout@v4-style tag pin becomes a full-commit-SHA pin with the exact version in a comment (checkout v4.4.0, setup-go v5.6.0, setup-node v4.4.0, setup-java v4.9.1, cache v3.5.0, upload-artifact v3.2.2, download-artifact v3.1.0). From a Forgejo runner everything on github.com is third-party; a moved tag silently changes what runs — including the signing jobs holding COSIGN_PRIVATE_KEY. Fixes #12

Checksum-verify fetched binaries — cosign, timoni, flux, Android cmdline-tools, and protoc downloads now verify a hard-coded sha256 before use (11 verification lines). cosign/timoni/flux hashes cross-checked against the projects' official checksum files; Google/protobuf publish none, so those were computed from two independent TLS downloads. Piped curl | tar installs restructured to download → verify → extract. No tool versions changed. Fixes #13

The legacy .github/workflows/ directory is untouched.

🤖 Generated with Claude Code

Two supply-chain gaps in `.gitea/workflows/`: **Digest-pin `actions/*`** — every `actions/checkout@v4`-style tag pin becomes a full-commit-SHA pin with the exact version in a comment (checkout v4.4.0, setup-go v5.6.0, setup-node v4.4.0, setup-java v4.9.1, cache v3.5.0, upload-artifact v3.2.2, download-artifact v3.1.0). From a Forgejo runner everything on github.com is third-party; a moved tag silently changes what runs — including the signing jobs holding `COSIGN_PRIVATE_KEY`. Fixes #12 **Checksum-verify fetched binaries** — cosign, timoni, flux, Android cmdline-tools, and protoc downloads now verify a hard-coded sha256 before use (11 verification lines). cosign/timoni/flux hashes cross-checked against the projects' official checksum files; Google/protobuf publish none, so those were computed from two independent TLS downloads. Piped `curl | tar` installs restructured to download → verify → extract. No tool versions changed. Fixes #13 The legacy `.github/workflows/` directory is untouched. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
ci: pin actions by digest and verify tool downloads
All checks were successful
check / web (push) Successful in 1m48s
check / go (push) Successful in 2m8s
android / build (pull_request) Successful in 4m33s
bc23e6d2db
A moved tag or a tampered download silently changes what CI runs —
including the signing jobs, where the compromise would ride straight
into a signed release. Pinning every actions/* step to a full commit
digest (version recorded in a trailing comment) and hard-coding the
sha256 of every curl-fetched binary (cosign, timoni, flux, Android
cmdline-tools, protoc) makes the workflows reproducible and
tamper-evident: nothing runs that was not reviewed here. The cosign,
timoni and flux hashes were cross-checked against the projects'
published checksum files, then hard-coded — CI never fetches a
checksum from the same origin it is meant to distrust.

Fixes #12
Fixes #13
nalum force-pushed ci/pin-actions-and-tools from bc23e6d2db
All checks were successful
check / web (push) Successful in 1m48s
check / go (push) Successful in 2m8s
android / build (pull_request) Successful in 4m33s
to a805eb451f
Some checks failed
check / go (push) Has been cancelled
check / web (push) Has been cancelled
tag / tag (push) Has been cancelled
android / build (pull_request) Successful in 4m57s
android / build (push) Has been cancelled
2026-08-13 11:33:32 +00:00
Compare
nalum scheduled this pull request to auto merge when all checks succeed 2026-08-13 11:34:03 +00:00
nalum merged commit a805eb451f into main 2026-08-13 11:39:26 +00:00
nalum deleted branch ci/pin-actions-and-tools 2026-08-13 11:39:26 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app!28
No description provided.