Skip to content

fix: pin GitHub Actions by SHA - #2464

Merged
fricoben merged 2 commits into
mainfrom
security/pin-actions
Sep 30, 2026
Merged

fricoben merged 2 commits into
mainfrom
security/pin-actions

Conversation

@fricoben

Copy link
Copy Markdown
Contributor

Pins every third-party GitHub Action to an immutable commit SHA, updates the generated verification specification and tests, and documents CI dependencies as operational trust boundaries. The fork-workflow approval setting was tightened separately so every external contributor requires approval. Verification: make check passed, including 704 Python tests and all repository checks.

@fricoben
fricoben requested a review from Th0rgal as a code owner September 30, 2026 11:09

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OpenCodeReview first-pass review

🟠 3 finding(s) (1 medium / 2 low) — see inline comments.

✅ Posted 3 inline comment(s).

OCR pilot metrics & packet coverage

OCR pilot metrics

  • Routing: config-docs (router-v11)
  • Changed files: 19 supported / 19 total; Lean 0, trust docs 2, workflow/scripts 17, contracts 0, docs 0
  • Changed lines: 435 supported; thresholds large Lean >=3 files or >800 lines
  • OCR: status success; comments 3; files 19; tokens 1282310; tool calls 92; warnings 0; duration 482s
  • Largest changed files: .github/workflows/verify.yml (+57/-57), scripts/verify_sync_spec_source.py (+46/-46), scripts/verify_sync_spec.json (+40/-40), scripts/test_check_verify_sync.py (+34/-34), docs/TRUST_ASSUMPTIONS.md (+15/-0)

Pilot mode: advisory only. Codex Review remains the merge gate.

Comment thread docs/AXIOMS.md
Comment thread docs/TRUST_ASSUMPTIONS.md
Comment thread scripts/test_check_verify_sync.py

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OpenCodeReview first-pass review

🟠 3 finding(s) (3 low) — see inline comments.

✅ Posted 3 inline comment(s).

OCR pilot metrics & packet coverage

OCR pilot metrics

  • Routing: config-docs (router-v11)
  • Changed files: 19 supported / 19 total; Lean 0, trust docs 2, workflow/scripts 17, contracts 0, docs 0
  • Changed lines: 435 supported; thresholds large Lean >=3 files or >800 lines
  • OCR: status success; comments 3; files 19; tokens 1021831; tool calls 79; warnings 0; duration 771s
  • Largest changed files: .github/workflows/verify.yml (+57/-57), scripts/verify_sync_spec_source.py (+46/-46), scripts/verify_sync_spec.json (+40/-40), scripts/test_check_verify_sync.py (+34/-34), docs/TRUST_ASSUMPTIONS.md (+15/-0)

Pilot mode: advisory only. Codex Review remains the merge gate.

Comment thread .github/workflows/ocr-review.yml
Comment thread .github/workflows/ocr-review.yml
Comment thread scripts/verify_sync_spec_source.py
@fricoben
fricoben merged commit 85e0262 into main Sep 30, 2026
9 of 10 checks passed
@fricoben
fricoben deleted the security/pin-actions branch September 30, 2026 11:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant