Skip to content

fix: pin GitHub Actions to full commit SHAs - #44

Merged
Traky12 merged 3 commits into
mainfrom
security/pin-actions-2026-10-02
Oct 2, 2026
Merged

Traky12 merged 3 commits into
mainfrom
security/pin-actions-2026-10-02

Conversation

@Traky12

@Traky12 Traky12 commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Qué cambia y por qué

Remediación de seguridad según docs/governance/PRE-MERGE-REVIEW-PROTOCOL.md (Castuo-system).

  • Todo uses: externo fijado a SHA completo de 40 caracteres + # vX.Y.Z (los SHA se resolvieron vía API: la etiqueta apunta a ese commit; verified registrado).
  • trivy-action@v0.20.0 y @v0.35.0 → v0.36.0 por SHA. La v0.20.0 está dentro del rango comprometido (GHSA-69fq-xp46-6x23), aunque Dependabot no lo marcaba aquí.
  • scripts/goldfish-execute.sh: trivy-action@master → SHA.
  • Repo congelado a nivel de features hasta G2; esto es un parche de seguridad (autorizado según PORTFOLIO).
  • Coordinación con la baseline chore(security): add security & traceability baseline files #36: esa PR añade .github/dependabot.yml (con github-actions, que mantendrá estos SHA) y .github/workflows/secret-scan.yml con actions/checkout@v4 sin fijar. Tras mergear ambas, fijar esa línea (check_action_pins.py la detectará).

Revisión pre-merge (resumen A–F)

A. Identidad: head 271215b5f1b9686469d1d8376e6b297cb4b50634 · rama security/pin-actions-2026-10-02 · base main 3d281281d521475fd2313c699b184e1170c46d87.

B. Alcance: 34 files changed, 111 insertions(+), 111 deletions(-). Ficheros de workflow: 33. Solo se sustituyen líneas uses: 1:1. No cambia permisos, triggers, secretos, despliegue, infraestructura ni código de negocio.

C. Actions: check_action_pins.py → check_action_pins: 0 referencias mutables. Commits sin firma verificada upstream: azure/setup-kubectl v4.0.1 y SamKirkland/FTP-Deploy-Action v4.4.0 (solo se registra).

D. Dependencias:

  • No aplica (solo workflows).

E. PRs relacionados (ninguno cerrado):

PR Título Solape Clasificación
#41 fix(ci): visual summary as workflow artifact (immutable releases) 1 fichero(s) en común UNKNOWN: revisar antes del merge
#24 fix(ci): repair Agent Sync Hardening, Thingsdata, and Visual Summary w 2 fichero(s) en común UNKNOWN: revisar antes del merge
#21 feat(casto): bounded assurance quickstart and explicit TRL9 gate 1 fichero(s) en común UNKNOWN: revisar antes del merge
#20 fix(ci): repair pytest resolution lint scope and drift detection 1 fichero(s) en común UNKNOWN: revisar antes del merge
#6 Bump aquasecurity/trivy-action from 0.20.0 to 0.35.0 in /.github/workf 3 fichero(s) en común UNKNOWN: revisar antes del merge

F. CI: Actions bloqueado por facturación en repos privados desde ≥2026-08-17. Si los checks salen rojos sin arrancar, no cuentan ni como verde ni como fallo de código. Hay que relanzarlos sobre 271215b5f1b9 cuando se resuelva el bloqueo.

Alertas Dependabot abiertas en el momento del PR: 0. Solo se dan por resueltas cuando GitHub las cierre tras el merge.

Estado

Listo para integrar. Remediación propuesta, revisada estáticamente; pendiente de CI funcional, aprobación requerida y merge normal autorizado por el owner, ligado a este SHA.

🤖 Generated with Claude Code

Traky12 and others added 2 commits October 2, 2026 00:50
Every external uses: ref is replaced by the full 40-char commit SHA plus a
version comment, so a re-tagged upstream release cannot change what CI runs
(see trivy-action GHSA-69fq-xp46-6x23). Verified with
Castuo-system scripts/security/check_action_pins.py: 0 mutable refs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The security baseline PR #36 adds .github/dependabot.yml with the
github-actions ecosystem; keeping it here would conflict (add/add).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 22:57
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

🚦 48h Operativity: NO-GO

  • TRL9 Gate: NO-GO
  • Workflow result: success
  • Report file: artifacts/operativity/trl9/connection-48h-check-20261001-225737.md
  • Gate source: artifacts/operativity/trl9/go-nogo-status.md

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

🔒 Docker Security Audit

Status: success

Resumen Rápido

  • Auditoría Docker: success
  • Validación docker-compose: success
  • Tags fijos (no latest): ⚠️

Acciones si hay problemas

  • Ejecutar: make docker-harden
  • Verificar: make docker-verify-hardening
  • Re-auditar: make docker-audit --strict

Ver reporte completo en artefactos

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

🔍 Resumen de checks del PR #44

Workflow: E2E - Pull Request to Main
Conclusión: success
Run: https://github.com/Traky12/Cast-o/actions/runs/36938106081

  • ✅ Pasados: 23
  • ❌ Fallidos: 0
  • ⏭️ Omitidos/Neutral: 7

Detalle de checks

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

🔍 Resumen de checks del PR #44

Workflow: Validate All
Conclusión: success
Run: https://github.com/Traky12/Cast-o/actions/runs/36938106067

  • ✅ Pasados: 27
  • ❌ Fallidos: 0
  • ⏭️ Omitidos/Neutral: 8

Detalle de checks

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Functional CI remains blocked by billing, leaving the Trivy upgrade pending successful validation and human approval.

Review effort: Balanced
Findings: None

What changed in this PR

Hardens the repository’s CI and deployment workflows against supply-chain changes by pinning external GitHub Actions to immutable commits.

Changes:

  • Replaces mutable action references with full commit SHAs and release comments.
  • Upgrades Trivy to v0.36.0, including generated workflow templates.
  • Leaves triggers, permissions, and deployment configuration unchanged.
File Description
scripts/​goldfish-execute.sh Pins actions in generated workflows.
.github/​workflows/​vault-integration.yml Pins checkout.
.github/​workflows/​validate-all.yml Pins validation actions; upgrades Trivy.
.github/​workflows/​thingsdata-integration.yml Pins integration actions; upgrades Trivy.
.github/​workflows/​security-sql-injection.yml Pins checkout.
.github/​workflows/​security-rate-limiting.yml Pins checkout and Python setup.
.github/​workflows/​security-mfa.yml Pins checkout, Python setup, and TruffleHog.
.github/​workflows/​security-jwt.yml Pins checkout and Python setup.
.github/​workflows/​satellite-ci.yml Pins checkout and Python setup.
.github/​workflows/​sabionda-sync.yml Pins checkout.
.github/​workflows/​reconcile-ci.yml Pins checkout and artifact upload.
.github/​workflows/​notify-workflow-failure.yml Pins GitHub Script.
.github/​workflows/​github-operativity-certification.yml Pins checkout, Python setup, and artifact upload.
.github/​workflows/​generate-visual-summary.yml Pins summary and release actions.
.github/​workflows/​e2e-smoke-traces.yml Pins checkout and Python setup.
.github/​workflows/​e2e-release.yml Pins release, SSH, and email actions.
.github/​workflows/​e2e-merge.yml Pins setup, artifact, and email actions.
.github/​workflows/​e2e-first-sale.yml Pins artifact upload.
.github/​workflows/​e2e-first-pr.yml Pins checkout, runtime setup, and artifact upload.
.github/​workflows/​e2e-first-commit.yml Pins bootstrap actions; upgrades Trivy.
.github/​workflows/​docker-security.yml Pins Docker audit actions.
.github/​workflows/​docker-image.yml Pins checkout and Python setup.
.github/​workflows/​deploy-to-hetzner.yml Pins build, registry, and Kubernetes actions.
.github/​workflows/​deploy-staging.yml Pins checkout.
.github/​workflows/​deploy-hetzner-staging.yml Pins checkout, Python setup, and SSH.
.github/​workflows/​data-timescaledb-ha.yml Pins checkout and Python setup.
.github/​workflows/​ci-python.yml Pins Python CI actions.
.github/​workflows/​ci-js.yml Pins JavaScript CI actions.
.github/​workflows/​cd-deploy.yml Pins checkout.
.github/​workflows/​castuo-architecture-surface-check.yml Pins checkout.
.github/​workflows/​ai-code-analysis.yml Pins checkout and GitHub Script.
.github/​workflows/​agent-sync-hardening.yml Pins setup and artifact transfer actions.
.github/​workflows/​add-pr-comment.yml Pins GitHub Script.
.github/​workflows/​48h-operativity.yml Pins checkout, artifact upload, and GitHub Script.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI balanced review requested due to automatic review settings October 2, 2026 14:53

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🚦 48h Operativity: NO-GO

  • TRL9 Gate: NO-GO
  • Workflow result: success
  • Report file: artifacts/operativity/trl9/connection-48h-check-20261002-145318.md
  • Gate source: artifacts/operativity/trl9/go-nogo-status.md

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🔒 Docker Security Audit

Status: success

Resumen Rápido

  • Auditoría Docker: success
  • Validación docker-compose: success
  • Tags fijos (no latest): ⚠️

Acciones si hay problemas

  • Ejecutar: make docker-harden
  • Verificar: make docker-verify-hardening
  • Re-auditar: make docker-audit --strict

Ver reporte completo en artefactos

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🔍 Resumen de checks del PR #44

Workflow: E2E - Pull Request to Main
Conclusión: success
Run: https://github.com/Traky12/Cast-o/actions/runs/37023017866

  • ✅ Pasados: 21
  • ❌ Fallidos: 0
  • ⏭️ Omitidos/Neutral: 7

Detalle de checks

@Traky12
Traky12 merged commit c7623bf into main Oct 2, 2026
34 checks passed

This branch was successfully deployed

1 active deployment
staging — b732c8da Deployed Oct 2, 2026 by Traky12 via deploy-staging #39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants