sec(ci): pin all GitHub Actions to commit SHAs - #536
Conversation
|
Warning Rate limit exceeded
You’ve run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (15)
📝 WalkthroughWalkthroughThis PR pins third-party GitHub Action ChangesGitHub Actions Supply Chain Security Hardening
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related issues
Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (2)
.github/workflows/rollback.yml (1)
55-55: ⚡ Quick winDisable credential persistence on checkout steps in this high-privilege workflow.
Add
with: persist-credentials: falseto eachactions/checkoutstep to reduce the exposure window for the GitHub token in privileged contexts. This applies to all 5 checkout steps in this file.Suggested patch pattern
- - name: Checkout code - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 + - name: Checkout code + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 + with: + persist-credentials: falseLocations: lines 55, 193, 246, 286, 326.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/rollback.yml at line 55, The workflow uses five actions/checkout steps (each that contains "uses: actions/checkout@...") that currently persist the GITHUB_TOKEN; update each checkout invocation to include a with: persist-credentials: false block so the token is not kept for later steps (i.e., add the key persist-credentials: false under the corresponding actions/checkout step in the rollback.yml for all occurrences so credential persistence is disabled in this high-privilege workflow)..github/workflows/database-migration.yml (1)
79-80: ⚡ Quick winDisable persisted Git credentials on checkout steps.
actions/checkoutpersists the token in local git config by default. This workflow doesn't need to push commits, so setpersist-credentials: falseon each checkout step to reduce token exposure surface.Suggested patch
- name: Checkout code uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 + with: + persist-credentials: falseAlso applies to lines 143-144, 214-215, and 275-276.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/database-migration.yml around lines 79 - 80, The checkout steps using actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 persist the GitHub token in local git config by default; update each checkout step (the ones using actions/checkout) to include persist-credentials: false so the workflow does not retain the token when it does not need to push. Make the same change for the other actions/checkout usages in this workflow file so all checkout steps set persist-credentials: false.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/ci.yml:
- Line 37: Update every actions/checkout step to disable persisted Git
credentials by adding persist-credentials: false to each checkout invocation
(i.e., the occurrences of uses: actions/checkout@... such as the one shown with
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5); change all
checkout steps listed (lines referenced in the review) so they include
persist-credentials: false under the uses entry to prevent the GitHub token from
being left in git config.
---
Nitpick comments:
In @.github/workflows/database-migration.yml:
- Around line 79-80: The checkout steps using
actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 persist the GitHub
token in local git config by default; update each checkout step (the ones using
actions/checkout) to include persist-credentials: false so the workflow does not
retain the token when it does not need to push. Make the same change for the
other actions/checkout usages in this workflow file so all checkout steps set
persist-credentials: false.
In @.github/workflows/rollback.yml:
- Line 55: The workflow uses five actions/checkout steps (each that contains
"uses: actions/checkout@...") that currently persist the GITHUB_TOKEN; update
each checkout invocation to include a with: persist-credentials: false block so
the token is not kept for later steps (i.e., add the key persist-credentials:
false under the corresponding actions/checkout step in the rollback.yml for all
occurrences so credential persistence is disabled in this high-privilege
workflow).
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 0d5fe2f0-58d6-410b-89c7-4f8d48632906
📒 Files selected for processing (15)
.github/workflows/aws_sanity.yml.github/workflows/azure_sanity.yml.github/workflows/ci.yml.github/workflows/cleanup-staging.yml.github/workflows/database-migration.yml.github/workflows/deploy-all.yml.github/workflows/deploy-aws-fargate.yml.github/workflows/deploy-aws-lambda.yml.github/workflows/deploy-azure.yml.github/workflows/deploy-gcp.yml.github/workflows/destroy-fargate-dev.yml.github/workflows/frontend-build-sentinel.yml.github/workflows/frontend-build.yml.github/workflows/pre-commit.yml.github/workflows/rollback.yml
All 11 actions/checkout uses defaulted to persist-credentials: true, leaving the GitHub token in git config after checkout. None of these jobs need persisted credentials for authenticated git operations. Set persist-credentials: false on every step to reduce the token exposure window. Fixes CodeRabbit finding (artipacked) on PR #536.
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai resolve |
✅ Actions performedComments resolved. Approval is disabled; enable |
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
Replace all `uses: org/action@tag` refs across every workflow file with `uses: org/action@<sha> # tag` pins. Several workflows referenced non-existent future versions (v5/v6/v7 for actions still on v4); these are corrected to the actual latest released tag while being SHA-pinned. Closes #415
All 11 actions/checkout uses defaulted to persist-credentials: true, leaving the GitHub token in git config after checkout. None of these jobs need persisted credentials for authenticated git operations. Set persist-credentials: false on every step to reduce the token exposure window. Fixes CodeRabbit finding (artipacked) on PR #536.
…ation All 5 actions/checkout steps in rollback.yml and all 4 in database-migration.yml defaulted to persist-credentials: true, leaving the GitHub token in git config for the remainder of each job. Neither workflow has any step that performs authenticated git operations after checkout (cloud auth is done via dedicated aws-actions/configure-aws-credentials, google-github-actions/auth, and azure/login actions). Setting persist-credentials: false on every checkout step closes the token exposure window. Fixes remaining CodeRabbit artipacked findings on PR #536 (nitpick comments on rollback.yml and database-migration.yml).
|
Addressed the remaining CodeRabbit
Branch rebased onto @coderabbitai review |
|
✅ Actions performedReview triggered.
|
…ded major The previous SHA-pin commit resolved each action to a commit in an older major version than the workflows were using (e.g. checkout pinned to v4.3.1 while the branch used v5, configure-aws-credentials pinned to v4.3.1 while the branch used v6, etc.). This corrects every pin to the latest release within the same major that the base branch (feat/multicloud-web-frontend) was already on. No logic changes; SHA + version comment only. Actions corrected (old major -> correct major): actions/checkout v4.3.1 -> v5.0.1 (34 occurrences) actions/download-artifact v4.3.0 -> v7.0.0 (4 occurrences) actions/upload-artifact v4.6.2 -> v6.0.0 (9 occurrences) actions/setup-go v5.6.0 -> v6.4.0 (8 occurrences) actions/setup-node v4.4.0 -> v6.4.0 (3 occurrences) actions/setup-python v5.6.0 -> v6.2.0 (1 occurrence) aws-actions/configure-aws-credentials v4.3.1 -> v6.1.1 (10 occurrences; standardises ALL to v6.1.1) azure/login v2.3.0 -> v3.0.0 (7 occurrences) docker/build-push-action v6.9.0 -> v7.2.0 (1 occurrence) docker/setup-buildx-action v3.9.0 -> v4.0.0 (2 occurrences) google-github-actions/auth v2.1.9 -> v3.0.0 (5 occurrences) google-github-actions/setup-gcloud v2.2.1 -> v3.0.1 (2 occurrences) hashicorp/setup-terraform v3.1.2 -> v4.0.1 (15 occurrences) codecov/codecov-action v5.5.4 -> v6.0.1 (1 occurrence) golangci/golangci-lint-action v6.5.2 -> v9.2.1 (1 occurrence) snyk/actions/golang v1.0.0 -> 0.4.0 (1 occurrence; base was on 0.x) securego/gosec v2.22.9 -> v2.26.1 (1 occurrence; updated to latest v2) github/codeql-action v4.35.5 -> v4.36.0 (2 occurrences; updated to latest v4) All 23 SHAs independently verified against their tags via GitHub API. No float tags remain. YAML validates on all 15 files.
SHA-pin regression fixThe original pinning commit resolved every action to a commit SHA in an older major version than the workflows were actually using. This fix corrects all pins to the latest release within the same major that Corrected pins
Unchanged (already correct)
VerificationAll 23 SHAs independently confirmed against their tags via @coderabbitai review |
🧩 Analysis chainI'll spot-check a few of the high-privilege action SHA→tag mappings to validate accuracy before triggering the review. 🏁 Script executed: Length of output: 1543 The direct 🏁 Script executed: Length of output: 842
All other 13 pins matched on the first pass. The full set of 18 corrected SHA pins is accurate. Triggering the incremental review now. (╯°□°)╯ 🐇 ✓ ✅ Actions performedReview triggered.
|
* sec(ci): pin all GitHub Actions to commit SHAs (#415) Replace all `uses: org/action@tag` refs across every workflow file with `uses: org/action@<sha> # tag` pins. Several workflows referenced non-existent future versions (v5/v6/v7 for actions still on v4); these are corrected to the actual latest released tag while being SHA-pinned. Closes #415 * fix(ci): disable credential persistence on all checkout steps All 11 actions/checkout uses defaulted to persist-credentials: true, leaving the GitHub token in git config after checkout. None of these jobs need persisted credentials for authenticated git operations. Set persist-credentials: false on every step to reduce the token exposure window. Fixes CodeRabbit finding (artipacked) on PR #536. * fix(ci): disable credential persistence in rollback and database-migration All 5 actions/checkout steps in rollback.yml and all 4 in database-migration.yml defaulted to persist-credentials: true, leaving the GitHub token in git config for the remainder of each job. Neither workflow has any step that performs authenticated git operations after checkout (cloud auth is done via dedicated aws-actions/configure-aws-credentials, google-github-actions/auth, and azure/login actions). Setting persist-credentials: false on every checkout step closes the token exposure window. Fixes remaining CodeRabbit artipacked findings on PR #536 (nitpick comments on rollback.yml and database-migration.yml). * fix(ci): pin actions to latest SHA of the in-use major, not a downgraded major The previous SHA-pin commit resolved each action to a commit in an older major version than the workflows were using (e.g. checkout pinned to v4.3.1 while the branch used v5, configure-aws-credentials pinned to v4.3.1 while the branch used v6, etc.). This corrects every pin to the latest release within the same major that the base branch (feat/multicloud-web-frontend) was already on. No logic changes; SHA + version comment only. Actions corrected (old major -> correct major): actions/checkout v4.3.1 -> v5.0.1 (34 occurrences) actions/download-artifact v4.3.0 -> v7.0.0 (4 occurrences) actions/upload-artifact v4.6.2 -> v6.0.0 (9 occurrences) actions/setup-go v5.6.0 -> v6.4.0 (8 occurrences) actions/setup-node v4.4.0 -> v6.4.0 (3 occurrences) actions/setup-python v5.6.0 -> v6.2.0 (1 occurrence) aws-actions/configure-aws-credentials v4.3.1 -> v6.1.1 (10 occurrences; standardises ALL to v6.1.1) azure/login v2.3.0 -> v3.0.0 (7 occurrences) docker/build-push-action v6.9.0 -> v7.2.0 (1 occurrence) docker/setup-buildx-action v3.9.0 -> v4.0.0 (2 occurrences) google-github-actions/auth v2.1.9 -> v3.0.0 (5 occurrences) google-github-actions/setup-gcloud v2.2.1 -> v3.0.1 (2 occurrences) hashicorp/setup-terraform v3.1.2 -> v4.0.1 (15 occurrences) codecov/codecov-action v5.5.4 -> v6.0.1 (1 occurrence) golangci/golangci-lint-action v6.5.2 -> v9.2.1 (1 occurrence) snyk/actions/golang v1.0.0 -> 0.4.0 (1 occurrence; base was on 0.x) securego/gosec v2.22.9 -> v2.26.1 (1 occurrence; updated to latest v2) github/codeql-action v4.35.5 -> v4.36.0 (2 occurrences; updated to latest v4) All 23 SHAs independently verified against their tags via GitHub API. No float tags remain. YAML validates on all 15 files.
Summary
uses: org/action@tagreference in all 15 workflow files to an immutable commit SHA with the tag preserved as a comment (e.g.uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1), eliminating supply-chain risk from mutable tag refs.actions/checkout@v5,azure/login@v3,aws-actions/configure-aws-credentials@v6) — these are replaced with SHAs of the actual latest released tag..github/workflows/*.ymlfiles updated; no logic or behaviour changes.Closes #415
Test plan
grep "uses:" .github/workflows/*.yml | grep -v "@[0-9a-f]\{40\}" | grep -v "uses: ./.github"returns empty (all refs are SHA-pinned)python3 -c "import yaml, sys; [yaml.safe_load(open(f)) for f in sys.argv[1:]]" .github/workflows/*.yml)Summary by CodeRabbit