ci: Pin GitHub Actions to immutable SHAs to prevent supply chain risks - #68
Merged
SignalLayerLabs merged 2 commits intoAug 25, 2026
Merged
Conversation
vibemasshq-dev
force-pushed
the
ci/pin-github-actions
branch
from
August 22, 2026 23:17
18195af to
788c32c
Compare
SignalLayerLabs
requested changes
Aug 24, 2026
SignalLayerLabs
left a comment
Owner
There was a problem hiding this comment.
Thanks for the contribution — pinning the Actions to immutable SHAs makes sense.
CI is currently failing because tests/evaluation/test_swebench_lite_workflow.py still explicitly expects:
actions/upload-artifact@v7
while this PR correctly replaces it with the pinned SHA.
Please update the test accordingly — ideally validating that upload-artifact is pinned to a 40-character commit SHA rather than depending on a mutable version tag — and rerun CI.
Once CI is green, this looks good to merge.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hey! 👋 I was exploring Marginal (the Claude Code integration looks super interesting!) and I ran the repository through a security and architecture scanner we are building called VibeMass.
I noticed a minor supply-chain vulnerability in your CI/CD workflows, so I wanted to quickly patch it for you.
1. Security Fix: Mutable GitHub Action Tags
Workflows like
ci.yml,codeql.yml,release.yml, andswebench-lite-canary.ymlwere using mutable tags like@v6and@v4. If any of those upstream action repositories are ever compromised, an attacker could silently inject malware into your builds.Fix: I’ve pinned your GitHub Actions to their exact 40-character commit SHAs to guarantee supply chain security.
2. Architecture Heads-Up (No Action Required)
As a side note, the scanner's Architecture agent flagged a few heavy "God Files" that might become bottlenecks as you scale:
src/marginal/privacy.pyandsrc/marginal/governance_ledger.pyare getting massive. The agent flagged that having all privacy and governance logic centralized in single files makes it much harder to audit for compliance and adapt to new regulations without risking side effects across the whole system.src/marginal/integrations/codex/service.pyas a monolithic service that might slow down feature velocity.Just wanted to leave that as a helpful architectural breadcrumb. Keep up the great work on the project! 🚀