ci: harden main.yml workflow against supply-chain risks#1306
Open
erickcestari wants to merge 1 commit into
Open
ci: harden main.yml workflow against supply-chain risks#1306erickcestari wants to merge 1 commit into
erickcestari wants to merge 1 commit into
Conversation
Apply least-privilege and standard hardening to the CI workflow: - Set top-level `permissions: contents: read` so `GITHUB_TOKEN` no longer defaults to broad read/write across the repo. - Pass `github.base_ref` and `github.repository` via env vars in the `check-commits` job to prevent shell injection via expression interpolation in `run:` blocks. - Pin third-party `jpribyl/action-docker-layer-caching` to a full commit SHA so a tag retag cannot swap in unreviewed code. - Bump `actions/checkout@v3` to `@v4` in `sqlc-check` for consistency with the rest of the workflow. - Use `yarn install --frozen-lockfile` for all dependency installs so CI fails on lockfile drift instead of silently resolving new package versions.
|
Note Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported. |
ViktorT-11
approved these changes
May 25, 2026
ViktorT-11
left a comment
Contributor
There was a problem hiding this comment.
Thanks for this, looks good to me 🎉!
|
@ellemouton: review reminder |
ellemouton
approved these changes
Jun 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Apply least-privilege and standard hardening to the CI workflow:
permissions: contents: readsoGITHUB_TOKENno longer defaults to broad read/write across the repo.github.base_refandgithub.repositoryvia env vars in thecheck-commitsjob to prevent shell injection via expression interpolation inrun:blocks.jpribyl/action-docker-layer-cachingto a full commit SHA so a tag retag cannot swap in unreviewed code.actions/checkout@v3to@v4insqlc-checkfor consistency with the rest of the workflow.yarn install --frozen-lockfilefor all dependency installs so CI fails on lockfile drift instead of silently resolving new package versions.