Skip to content

Add SECURITY.md and harden workflow permissions and action pinning #300

Description

@allen0099

Problem

A few low-cost hardening items are missing:

  • No SECURITY.md. Private vulnerability reporting is enabled on the repository, but nothing tells a reporter to use it instead of opening a public issue, or which versions receive fixes.
  • Workflows without a permissions: block. lint.yml, docs.yml and renovate-validate.yml run with the repository's default GITHUB_TOKEN permissions. The other workflows already declare theirs.
  • persist-credentials. Only release.yml sets persist-credentials: false on actions/checkout; the other jobs leave the token in .git/config for every later step.
  • Actions pinned by tag. Third-party actions (astral-sh/setup-uv, JamesIves/github-pages-deploy-action, softprops/action-gh-release, pypa/gh-action-pypi-publish@release/v1) are referenced by mutable tags or branches. Renovate can keep SHA pins up to date (helpers:pinGitHubActionDigests).

Proposal

  • Add SECURITY.md pointing to private vulnerability reporting and stating the supported version line.
  • Add permissions: contents: read at the top of the three workflows.
  • Set persist-credentials: false on every checkout that does not push.
  • Pin actions to commit SHAs, at least in release.yml, and enable the Renovate preset.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ciCI workflows, test suite and toolingdocumentationImprovements or additions to documentationsecuritySecurity vulnerability or hardening

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions