Repository navigation
fix: pin GitHub Actions to full commit SHAs - #44
Merged
Merged
Conversation
Every external uses: ref is replaced by the full 40-char commit SHA plus a version comment, so a re-tagged upstream release cannot change what CI runs (see trivy-action GHSA-69fq-xp46-6x23). Verified with Castuo-system scripts/security/check_action_pins.py: 0 mutable refs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The security baseline PR #36 adds .github/dependabot.yml with the github-actions ecosystem; keeping it here would conflict (add/add). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
|
🚦 48h Operativity: NO-GO
|
Contributor
🔒 Docker Security AuditStatus: success Resumen Rápido
Acciones si hay problemas
|
Contributor
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Functional CI remains blocked by billing, leaving the Trivy upgrade pending successful validation and human approval.
Review effort: Balanced
Findings: None
What changed in this PR
Hardens the repository’s CI and deployment workflows against supply-chain changes by pinning external GitHub Actions to immutable commits.
Changes:
- Replaces mutable action references with full commit SHAs and release comments.
- Upgrades Trivy to v0.36.0, including generated workflow templates.
- Leaves triggers, permissions, and deployment configuration unchanged.
| File | Description |
|---|---|
| scripts/goldfish-execute.sh | Pins actions in generated workflows. |
| .github/workflows/vault-integration.yml | Pins checkout. |
| .github/workflows/validate-all.yml | Pins validation actions; upgrades Trivy. |
| .github/workflows/thingsdata-integration.yml | Pins integration actions; upgrades Trivy. |
| .github/workflows/security-sql-injection.yml | Pins checkout. |
| .github/workflows/security-rate-limiting.yml | Pins checkout and Python setup. |
| .github/workflows/security-mfa.yml | Pins checkout, Python setup, and TruffleHog. |
| .github/workflows/security-jwt.yml | Pins checkout and Python setup. |
| .github/workflows/satellite-ci.yml | Pins checkout and Python setup. |
| .github/workflows/sabionda-sync.yml | Pins checkout. |
| .github/workflows/reconcile-ci.yml | Pins checkout and artifact upload. |
| .github/workflows/notify-workflow-failure.yml | Pins GitHub Script. |
| .github/workflows/github-operativity-certification.yml | Pins checkout, Python setup, and artifact upload. |
| .github/workflows/generate-visual-summary.yml | Pins summary and release actions. |
| .github/workflows/e2e-smoke-traces.yml | Pins checkout and Python setup. |
| .github/workflows/e2e-release.yml | Pins release, SSH, and email actions. |
| .github/workflows/e2e-merge.yml | Pins setup, artifact, and email actions. |
| .github/workflows/e2e-first-sale.yml | Pins artifact upload. |
| .github/workflows/e2e-first-pr.yml | Pins checkout, runtime setup, and artifact upload. |
| .github/workflows/e2e-first-commit.yml | Pins bootstrap actions; upgrades Trivy. |
| .github/workflows/docker-security.yml | Pins Docker audit actions. |
| .github/workflows/docker-image.yml | Pins checkout and Python setup. |
| .github/workflows/deploy-to-hetzner.yml | Pins build, registry, and Kubernetes actions. |
| .github/workflows/deploy-staging.yml | Pins checkout. |
| .github/workflows/deploy-hetzner-staging.yml | Pins checkout, Python setup, and SSH. |
| .github/workflows/data-timescaledb-ha.yml | Pins checkout and Python setup. |
| .github/workflows/ci-python.yml | Pins Python CI actions. |
| .github/workflows/ci-js.yml | Pins JavaScript CI actions. |
| .github/workflows/cd-deploy.yml | Pins checkout. |
| .github/workflows/castuo-architecture-surface-check.yml | Pins checkout. |
| .github/workflows/ai-code-analysis.yml | Pins checkout and GitHub Script. |
| .github/workflows/agent-sync-hardening.yml | Pins setup and artifact transfer actions. |
| .github/workflows/add-pr-comment.yml | Pins GitHub Script. |
| .github/workflows/48h-operativity.yml | Pins checkout, artifact upload, and GitHub Script. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Contributor
|
🚦 48h Operativity: NO-GO
|
Contributor
🔒 Docker Security AuditStatus: success Resumen Rápido
Acciones si hay problemas
|
Contributor
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Qué cambia y por qué
Remediación de seguridad según
docs/governance/PRE-MERGE-REVIEW-PROTOCOL.md(Castuo-system).uses:externo fijado a SHA completo de 40 caracteres +# vX.Y.Z(los SHA se resolvieron vía API: la etiqueta apunta a ese commit;verifiedregistrado).trivy-action@v0.20.0y@v0.35.0→ v0.36.0 por SHA. La v0.20.0 está dentro del rango comprometido (GHSA-69fq-xp46-6x23), aunque Dependabot no lo marcaba aquí.scripts/goldfish-execute.sh:trivy-action@master→ SHA..github/dependabot.yml(con github-actions, que mantendrá estos SHA) y.github/workflows/secret-scan.ymlconactions/checkout@v4sin fijar. Tras mergear ambas, fijar esa línea (check_action_pins.pyla detectará).Revisión pre-merge (resumen A–F)
A. Identidad: head
271215b5f1b9686469d1d8376e6b297cb4b50634· ramasecurity/pin-actions-2026-10-02· basemain3d281281d521475fd2313c699b184e1170c46d87.B. Alcance: 34 files changed, 111 insertions(+), 111 deletions(-). Ficheros de workflow: 33. Solo se sustituyen líneas
uses:1:1. No cambia permisos, triggers, secretos, despliegue, infraestructura ni código de negocio.C. Actions:
check_action_pins.py→ check_action_pins: 0 referencias mutables. Commits sin firma verificada upstream:azure/setup-kubectlv4.0.1 ySamKirkland/FTP-Deploy-Actionv4.4.0 (solo se registra).D. Dependencias:
E. PRs relacionados (ninguno cerrado):
F. CI: Actions bloqueado por facturación en repos privados desde ≥2026-08-17. Si los checks salen rojos sin arrancar, no cuentan ni como verde ni como fallo de código. Hay que relanzarlos sobre
271215b5f1b9cuando se resuelva el bloqueo.Alertas Dependabot abiertas en el momento del PR: 0. Solo se dan por resueltas cuando GitHub las cierre tras el merge.
Estado
Listo para integrar. Remediación propuesta, revisada estáticamente; pendiente de CI funcional, aprobación requerida y merge normal autorizado por el owner, ligado a este SHA.
🤖 Generated with Claude Code