Skip to content

ci: Pin GitHub Actions to immutable SHAs to prevent supply chain risks - #68

Merged
SignalLayerLabs merged 2 commits into
SignalLayerLabs:mainfrom
vibemasshq-dev:ci/pin-github-actions
Aug 25, 2026
Merged

SignalLayerLabs merged 2 commits into
SignalLayerLabs:mainfrom
vibemasshq-dev:ci/pin-github-actions

Conversation

@vibemasshq-dev

Copy link
Copy Markdown
Contributor

Hey! 👋 I was exploring Marginal (the Claude Code integration looks super interesting!) and I ran the repository through a security and architecture scanner we are building called VibeMass.

I noticed a minor supply-chain vulnerability in your CI/CD workflows, so I wanted to quickly patch it for you.

1. Security Fix: Mutable GitHub Action Tags

Workflows like ci.yml, codeql.yml, release.yml, and swebench-lite-canary.yml were using mutable tags like @v6 and @v4. If any of those upstream action repositories are ever compromised, an attacker could silently inject malware into your builds.
Fix: I’ve pinned your GitHub Actions to their exact 40-character commit SHAs to guarantee supply chain security.

2. Architecture Heads-Up (No Action Required)

As a side note, the scanner's Architecture agent flagged a few heavy "God Files" that might become bottlenecks as you scale:

  • src/marginal/privacy.py and src/marginal/governance_ledger.py are getting massive. The agent flagged that having all privacy and governance logic centralized in single files makes it much harder to audit for compliance and adapt to new regulations without risking side effects across the whole system.
  • It also flagged src/marginal/integrations/codex/service.py as a monolithic service that might slow down feature velocity.

Just wanted to leave that as a helpful architectural breadcrumb. Keep up the great work on the project! 🚀

@SignalLayerLabs SignalLayerLabs left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the contribution — pinning the Actions to immutable SHAs makes sense.

CI is currently failing because tests/evaluation/test_swebench_lite_workflow.py still explicitly expects:

actions/upload-artifact@v7

while this PR correctly replaces it with the pinned SHA.

Please update the test accordingly — ideally validating that upload-artifact is pinned to a 40-character commit SHA rather than depending on a mutable version tag — and rerun CI.

Once CI is green, this looks good to merge.

@SignalLayerLabs
SignalLayerLabs merged commit 15d1f6b into SignalLayerLabs:main Aug 25, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants