Skip to content

sec(ci): pin all GitHub Actions to commit SHAs - #536

Merged
cristim merged 4 commits into
feat/multicloud-web-frontendfrom
sec/ci-sha-pins
May 22, 2026
Merged

cristim merged 4 commits into
feat/multicloud-web-frontendfrom
sec/ci-sha-pins

Conversation

@cristim

@cristim cristim commented May 20, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Pin every uses: org/action@tag reference in all 15 workflow files to an immutable commit SHA with the tag preserved as a comment (e.g. uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1), eliminating supply-chain risk from mutable tag refs.
  • Correct several workflows that referenced non-existent future versions (e.g. actions/checkout@v5, azure/login@v3, aws-actions/configure-aws-credentials@v6) — these are replaced with SHAs of the actual latest released tag.
  • All 15 .github/workflows/*.yml files updated; no logic or behaviour changes.

Closes #415

Test plan

  • Verify grep "uses:" .github/workflows/*.yml | grep -v "@[0-9a-f]\{40\}" | grep -v "uses: ./.github" returns empty (all refs are SHA-pinned)
  • Confirm YAML syntax is valid (python3 -c "import yaml, sys; [yaml.safe_load(open(f)) for f in sys.argv[1:]]" .github/workflows/*.yml)
  • Check CI passes on this PR

Summary by CodeRabbit

  • Chores
    • CI/CD workflows: pinned third‑party GitHub Action versions to specific commits across the pipeline for more deterministic, reproducible runs and improved stability.
    • No changes to workflow logic, triggers, or build/test/deploy behavior—only the action version references were made explicit.

Review Change Stack

@cristim cristim added triaged Item has been triaged priority/p2 Backlog-worthy severity/medium Moderate harm urgency/this-sprint Within the current sprint impact/internal Team-internal only effort/m Days type/security Security finding labels May 20, 2026
@coderabbitai

coderabbitai Bot commented May 20, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@cristim has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 8 minutes and 8 seconds before requesting another review.

You’ve run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 55c55788-b047-4ec5-ad64-631a78d32828

📥 Commits

Reviewing files that changed from the base of the PR and between 82e27fe and 3380eec.

📒 Files selected for processing (15)
  • .github/workflows/aws_sanity.yml
  • .github/workflows/azure_sanity.yml
  • .github/workflows/ci.yml
  • .github/workflows/cleanup-staging.yml
  • .github/workflows/database-migration.yml
  • .github/workflows/deploy-all.yml
  • .github/workflows/deploy-aws-fargate.yml
  • .github/workflows/deploy-aws-lambda.yml
  • .github/workflows/deploy-azure.yml
  • .github/workflows/deploy-gcp.yml
  • .github/workflows/destroy-fargate-dev.yml
  • .github/workflows/frontend-build-sentinel.yml
  • .github/workflows/frontend-build.yml
  • .github/workflows/pre-commit.yml
  • .github/workflows/rollback.yml
📝 Walkthrough

Walkthrough

This PR pins third-party GitHub Action uses: references to specific commit SHAs across all workflows, replacing floating major-version tags and leaving workflow triggers and job logic unchanged.

Changes

GitHub Actions Supply Chain Security Hardening

Layer / File(s) Summary
Core deployment credential & terraform setup pins
.github/workflows/deploy-aws-lambda.yml, deploy-aws-fargate.yml, deploy-azure.yml, deploy-gcp.yml
Pinned actions/checkout, cloud auth actions (aws-actions/configure-aws-credentials, azure/login, google-github-actions/auth), hashicorp/setup-terraform, and artifact upload/download uses: to specific commit SHAs.
CI pipeline tooling & scanners
.github/workflows/ci.yml
Pinned actions/checkout, actions/setup-go, Codecov, Docker setup-buildx/build-push, hashicorp/setup-terraform, security scanners (gosec, Trivy, tfsec), SARIF upload, Snyk, and Infracost uses: to commit SHAs across lint, test, build, scan, and cost jobs.
Cleanup, staging destroy, and rollback pins
.github/workflows/cleanup-staging.yml, destroy-fargate-dev.yml, rollback.yml, deploy-all.yml
Pinned checkout, cloud credential actions, Terraform setup (including v3.1.2 pins), and artifact actions to commit SHAs in cleanup and rollback workflows; a commented Slack action was similarly pinned.
Migration, validation, pre-commit, frontend, and sanity workflows
.github/workflows/database-migration.yml, pre-commit.yml, aws_sanity.yml, azure_sanity.yml, frontend-build.yml, frontend-build-sentinel.yml
Pinned checkout, language/setup actions (setup-go, setup-node, setup-python), actions/cache, auth/setup-gcloud, and artifact steps to commit SHAs without changing job commands or control flow.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related issues

Possibly related PRs

  • LeanerCloud/CUDly#552: Pins aws-actions/configure-aws-credentials to an immutable SHA in deploy-aws-lambda.yml (overlaps with this PR's change).

Poem

🐰 Whiskers twitch, I hop and pin,

No floating tags shall roam again,
Commits locked tight in every flow,
Pipelines safe where secrets go,
A rabbit's nod—secure we grow.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The PR title clearly and concisely summarizes the main change: pinning all GitHub Actions to commit SHAs for supply-chain security.
Linked Issues check ✅ Passed All code requirements from issue #415 are fully met: all 15 workflow files have GitHub Actions pinned to commit SHAs, high-privilege actions are secured, and tag corrections were applied.
Out of Scope Changes check ✅ Passed All changes are within scope of issue #415; only GitHub Actions version pinning was modified across workflow files with no unrelated logic changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch sec/ci-sha-pins

Comment @coderabbitai help to get the list of available commands and usage tips.

@cristim

cristim commented May 20, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 20, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented May 20, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 20, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (2)
.github/workflows/rollback.yml (1)

55-55: ⚡ Quick win

Disable credential persistence on checkout steps in this high-privilege workflow.

Add with: persist-credentials: false to each actions/checkout step to reduce the exposure window for the GitHub token in privileged contexts. This applies to all 5 checkout steps in this file.

Suggested patch pattern
-      - name: Checkout code
-        uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
+      - name: Checkout code
+        uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
+        with:
+          persist-credentials: false

Locations: lines 55, 193, 246, 286, 326.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/rollback.yml at line 55, The workflow uses five
actions/checkout steps (each that contains "uses: actions/checkout@...") that
currently persist the GITHUB_TOKEN; update each checkout invocation to include a
with: persist-credentials: false block so the token is not kept for later steps
(i.e., add the key persist-credentials: false under the corresponding
actions/checkout step in the rollback.yml for all occurrences so credential
persistence is disabled in this high-privilege workflow).
.github/workflows/database-migration.yml (1)

79-80: ⚡ Quick win

Disable persisted Git credentials on checkout steps.

actions/checkout persists the token in local git config by default. This workflow doesn't need to push commits, so set persist-credentials: false on each checkout step to reduce token exposure surface.

Suggested patch
       - name: Checkout code
         uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
+        with:
+          persist-credentials: false

Also applies to lines 143-144, 214-215, and 275-276.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/database-migration.yml around lines 79 - 80, The checkout
steps using actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 persist
the GitHub token in local git config by default; update each checkout step (the
ones using actions/checkout) to include persist-credentials: false so the
workflow does not retain the token when it does not need to push. Make the same
change for the other actions/checkout usages in this workflow file so all
checkout steps set persist-credentials: false.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ci.yml:
- Line 37: Update every actions/checkout step to disable persisted Git
credentials by adding persist-credentials: false to each checkout invocation
(i.e., the occurrences of uses: actions/checkout@... such as the one shown with
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5); change all
checkout steps listed (lines referenced in the review) so they include
persist-credentials: false under the uses entry to prevent the GitHub token from
being left in git config.

---

Nitpick comments:
In @.github/workflows/database-migration.yml:
- Around line 79-80: The checkout steps using
actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 persist the GitHub
token in local git config by default; update each checkout step (the ones using
actions/checkout) to include persist-credentials: false so the workflow does not
retain the token when it does not need to push. Make the same change for the
other actions/checkout usages in this workflow file so all checkout steps set
persist-credentials: false.

In @.github/workflows/rollback.yml:
- Line 55: The workflow uses five actions/checkout steps (each that contains
"uses: actions/checkout@...") that currently persist the GITHUB_TOKEN; update
each checkout invocation to include a with: persist-credentials: false block so
the token is not kept for later steps (i.e., add the key persist-credentials:
false under the corresponding actions/checkout step in the rollback.yml for all
occurrences so credential persistence is disabled in this high-privilege
workflow).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 0d5fe2f0-58d6-410b-89c7-4f8d48632906

📥 Commits

Reviewing files that changed from the base of the PR and between b1ea4b1 and 6b05961.

📒 Files selected for processing (15)
  • .github/workflows/aws_sanity.yml
  • .github/workflows/azure_sanity.yml
  • .github/workflows/ci.yml
  • .github/workflows/cleanup-staging.yml
  • .github/workflows/database-migration.yml
  • .github/workflows/deploy-all.yml
  • .github/workflows/deploy-aws-fargate.yml
  • .github/workflows/deploy-aws-lambda.yml
  • .github/workflows/deploy-azure.yml
  • .github/workflows/deploy-gcp.yml
  • .github/workflows/destroy-fargate-dev.yml
  • .github/workflows/frontend-build-sentinel.yml
  • .github/workflows/frontend-build.yml
  • .github/workflows/pre-commit.yml
  • .github/workflows/rollback.yml

Comment thread .github/workflows/ci.yml Outdated
cristim added a commit that referenced this pull request May 20, 2026
All 11 actions/checkout uses defaulted to persist-credentials: true,
leaving the GitHub token in git config after checkout. None of these jobs
need persisted credentials for authenticated git operations. Set
persist-credentials: false on every step to reduce the token exposure
window.

Fixes CodeRabbit finding (artipacked) on PR #536.
@cristim

cristim commented May 20, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 20, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented May 20, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai resolve

@coderabbitai

coderabbitai Bot commented May 20, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Comments resolved. Approval is disabled; enable reviews.request_changes_workflow to allow explicit top-level @coderabbitai resolve or @coderabbitai approve commands.

@cristim

cristim commented May 21, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 21, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented May 21, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 21, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented May 22, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 22, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

cristim added 3 commits May 22, 2026 15:07
Replace all `uses: org/action@tag` refs across every workflow file
with `uses: org/action@<sha> # tag` pins. Several workflows referenced
non-existent future versions (v5/v6/v7 for actions still on v4); these
are corrected to the actual latest released tag while being SHA-pinned.

Closes #415
All 11 actions/checkout uses defaulted to persist-credentials: true,
leaving the GitHub token in git config after checkout. None of these jobs
need persisted credentials for authenticated git operations. Set
persist-credentials: false on every step to reduce the token exposure
window.

Fixes CodeRabbit finding (artipacked) on PR #536.
…ation

All 5 actions/checkout steps in rollback.yml and all 4 in
database-migration.yml defaulted to persist-credentials: true, leaving
the GitHub token in git config for the remainder of each job. Neither
workflow has any step that performs authenticated git operations after
checkout (cloud auth is done via dedicated aws-actions/configure-aws-credentials,
google-github-actions/auth, and azure/login actions). Setting
persist-credentials: false on every checkout step closes the token
exposure window.

Fixes remaining CodeRabbit artipacked findings on PR #536 (nitpick
comments on rollback.yml and database-migration.yml).
@cristim
cristim force-pushed the sec/ci-sha-pins branch from 82e27fe to ff6229a Compare May 22, 2026 13:07
@cristim

cristim commented May 22, 2026

Copy link
Copy Markdown
Member Author

Addressed the remaining CodeRabbit persist-credentials: false findings from the latest review:

  • rollback.yml: added persist-credentials: false to all 5 actions/checkout steps (validate, rollback-aws-lambda, rollback-aws-fargate, rollback-gcp, rollback-azure jobs). None of these jobs have authenticated git operations after checkout; cloud auth is handled by the dedicated aws-actions/configure-aws-credentials, google-github-actions/auth, and azure/login steps.
  • database-migration.yml: added persist-credentials: false to all 4 actions/checkout steps (validate, migrate-aws, migrate-gcp, migrate-azure jobs). Same reasoning: no post-checkout git push or credential-dependent git operations.

Branch rebased onto feat/multicloud-web-frontend, pushed as ff6229a.

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 22, 2026

Copy link
Copy Markdown
Contributor

@cristim Thanks for the thorough follow-up! The additions of persist-credentials: false to all 9 remaining checkout steps across rollback.yml and database-migration.yml look well-reasoned — since neither file performs post-checkout authenticated git operations (cloud auth is delegated to the respective provider actions), disabling credential persistence is the right call and eliminates the token-exposure risk. Triggering a fresh review now.

✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

…ded major

The previous SHA-pin commit resolved each action to a commit in an older
major version than the workflows were using (e.g. checkout pinned to v4.3.1
while the branch used v5, configure-aws-credentials pinned to v4.3.1 while
the branch used v6, etc.). This corrects every pin to the latest release
within the same major that the base branch (feat/multicloud-web-frontend)
was already on. No logic changes; SHA + version comment only.

Actions corrected (old major -> correct major):
  actions/checkout              v4.3.1 -> v5.0.1    (34 occurrences)
  actions/download-artifact     v4.3.0 -> v7.0.0     (4 occurrences)
  actions/upload-artifact       v4.6.2 -> v6.0.0     (9 occurrences)
  actions/setup-go              v5.6.0 -> v6.4.0     (8 occurrences)
  actions/setup-node            v4.4.0 -> v6.4.0     (3 occurrences)
  actions/setup-python          v5.6.0 -> v6.2.0     (1 occurrence)
  aws-actions/configure-aws-credentials  v4.3.1 -> v6.1.1  (10 occurrences; standardises ALL to v6.1.1)
  azure/login                   v2.3.0 -> v3.0.0     (7 occurrences)
  docker/build-push-action      v6.9.0 -> v7.2.0     (1 occurrence)
  docker/setup-buildx-action    v3.9.0 -> v4.0.0     (2 occurrences)
  google-github-actions/auth    v2.1.9 -> v3.0.0     (5 occurrences)
  google-github-actions/setup-gcloud  v2.2.1 -> v3.0.1  (2 occurrences)
  hashicorp/setup-terraform     v3.1.2 -> v4.0.1     (15 occurrences)
  codecov/codecov-action        v5.5.4 -> v6.0.1     (1 occurrence)
  golangci/golangci-lint-action v6.5.2 -> v9.2.1     (1 occurrence)
  snyk/actions/golang           v1.0.0 -> 0.4.0      (1 occurrence; base was on 0.x)
  securego/gosec                v2.22.9 -> v2.26.1   (1 occurrence; updated to latest v2)
  github/codeql-action          v4.35.5 -> v4.36.0   (2 occurrences; updated to latest v4)

All 23 SHAs independently verified against their tags via GitHub API.
No float tags remain. YAML validates on all 15 files.
@cristim

cristim commented May 22, 2026

Copy link
Copy Markdown
Member Author

SHA-pin regression fix

The original pinning commit resolved every action to a commit SHA in an older major version than the workflows were actually using. This fix corrects all pins to the latest release within the same major that feat/multicloud-web-frontend was on before this PR.

Corrected pins

Action Old (downgraded) Corrected to Occurrences
actions/checkout v4.3.1 v5.0.1 (93cb6efe) 34
actions/download-artifact v4.3.0 v7.0.0 (37930b1c) 4
actions/upload-artifact v4.6.2 v6.0.0 (b7c566a7) 9
actions/setup-go v5.6.0 v6.4.0 (4a360112) 8
actions/setup-node v4.4.0 v6.4.0 (48b55a01) 3
actions/setup-python v5.6.0 v6.2.0 (a309ff8b) 1
aws-actions/configure-aws-credentials v4.3.1 (most places) v6.1.1 (d979d5b3) - standardized all 10
azure/login v2.3.0 v3.0.0 (532459ea) 7
docker/build-push-action v6.9.0 v7.2.0 (f9f3042f) 1
docker/setup-buildx-action v3.9.0 v4.0.0 (4d04d5d9) 2
google-github-actions/auth v2.1.9 v3.0.0 (7c6bc770) 5
google-github-actions/setup-gcloud v2.2.1 v3.0.1 (aa5489c8) 2
hashicorp/setup-terraform v3.1.2 v4.0.1 (dfe3c3f8) 15
codecov/codecov-action v5.5.4 v6.0.1 (e79a6962) 1
golangci/golangci-lint-action v6.5.2 v9.2.1 (82606bf2) 1
snyk/actions/golang v1.0.0 (bumped from base) 0.4.0 (b98d4986) - reverted to base major 1
securego/gosec v2.22.9 v2.26.1 (4a3bd8af) - updated to latest v2 1
github/codeql-action v4.35.5 v4.36.0 (7211b7c8) - updated to latest v4 2

Unchanged (already correct)

  • actions/cache - v4.3.0 (latest v4, correct)
  • aquasecurity/tfsec-action - v1.0.3 (latest v1, correct)
  • aquasecurity/trivy-action - v0.36.0 (latest 0.x, correct)
  • infracost/actions/setup - v4.1.0 (latest v4, correct)
  • slackapi/slack-github-action - v2.1.1 (latest v2, correct, commented out)

Verification

All 23 SHAs independently confirmed against their tags via gh api repos/<owner>/<repo>/commits/<tag>. No float tags remain. YAML validates on all 15 files.

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 22, 2026

Copy link
Copy Markdown
Contributor
🧩 Analysis chain

I'll spot-check a few of the high-privilege action SHA→tag mappings to validate accuracy before triggering the review.


🏁 Script executed:

#!/bin/bash
# Verify SHA pins for high-privilege actions

echo "=== actions/checkout v5.0.1 ==="
gh api repos/actions/checkout/commits/tags/v5.0.1 --jq '.sha' 2>/dev/null || \
gh api repos/actions/checkout/git/ref/tags/v5.0.1 --jq '.object.sha' 2>/dev/null

echo "=== aws-actions/configure-aws-credentials v6.1.1 ==="
gh api repos/aws-actions/configure-aws-credentials/git/ref/tags/v6.1.1 --jq '.object.sha' 2>/dev/null

echo "=== azure/login v3.0.0 ==="
gh api repos/azure/login/git/ref/tags/v3.0.0 --jq '.object.sha' 2>/dev/null

echo "=== google-github-actions/auth v3.0.0 ==="
gh api repos/google-github-actions/auth/git/ref/tags/v3.0.0 --jq '.object.sha' 2>/dev/null

echo "=== hashicorp/setup-terraform v4.0.1 ==="
gh api repos/hashicorp/setup-terraform/git/ref/tags/v4.0.1 --jq '.object.sha' 2>/dev/null

echo "=== actions/upload-artifact v6.0.0 ==="
gh api repos/actions/upload-artifact/git/ref/tags/v6.0.0 --jq '.object.sha' 2>/dev/null

echo "=== actions/download-artifact v7.0.0 ==="
gh api repos/actions/download-artifact/git/ref/tags/v7.0.0 --jq '.object.sha' 2>/dev/null

echo "=== actions/setup-go v6.4.0 ==="
gh api repos/actions/setup-go/git/ref/tags/v6.4.0 --jq '.object.sha' 2>/dev/null

echo "=== google-github-actions/setup-gcloud v3.0.1 ==="
gh api repos/google-github-actions/setup-gcloud/git/ref/tags/v3.0.1 --jq '.object.sha' 2>/dev/null

echo "=== docker/build-push-action v7.2.0 ==="
gh api repos/docker/build-push-action/git/ref/tags/v7.2.0 --jq '.object.sha' 2>/dev/null

echo "=== golangci/golangci-lint-action v9.2.1 ==="
gh api repos/golangci/golangci-lint-action/git/ref/tags/v9.2.1 --jq '.object.sha' 2>/dev/null

echo "=== github/codeql-action v4.36.0 ==="
gh api repos/github/codeql-action/git/ref/tags/codeql-bundle-v4.36.0 --jq '.object.sha' 2>/dev/null || \
gh api repos/github/codeql-action/git/ref/tags/v4.36.0 --jq '.object.sha' 2>/dev/null

echo "=== codecov/codecov-action v6.0.1 ==="
gh api repos/codecov/codecov-action/git/ref/tags/v6.0.1 --jq '.object.sha' 2>/dev/null

echo "=== snyk/actions tag 0.4.0 ==="
gh api repos/snyk/actions/git/ref/tags/0.4.0 --jq '.object.sha' 2>/dev/null

echo "=== securego/gosec v2.26.1 ==="
gh api repos/securego/gosec/git/ref/tags/v2.26.1 --jq '.object.sha' 2>/dev/null

echo "=== docker/setup-buildx-action v4.0.0 ==="
gh api repos/docker/setup-buildx-action/git/ref/tags/v4.0.0 --jq '.object.sha' 2>/dev/null

echo "=== actions/setup-node v6.4.0 ==="
gh api repos/actions/setup-node/git/ref/tags/v6.4.0 --jq '.object.sha' 2>/dev/null

echo "=== actions/setup-python v6.2.0 ==="
gh api repos/actions/setup-python/git/ref/tags/v6.2.0 --jq '.object.sha' 2>/dev/null

Length of output: 1543


The direct git/ref endpoint returns tag object SHAs for annotated tags. Let me dereference those to get the actual commit SHAs for the mismatching entries.


🏁 Script executed:

#!/bin/bash
# Dereference annotated tags to get commit SHAs for mismatching entries

dereference_tag() {
  local owner_repo=$1
  local tag=$2
  local ref_sha
  ref_sha=$(gh api "repos/${owner_repo}/git/ref/tags/${tag}" --jq '.object.sha' 2>/dev/null)
  local ref_type
  ref_type=$(gh api "repos/${owner_repo}/git/ref/tags/${tag}" --jq '.object.type' 2>/dev/null)
  
  echo "Tag ref SHA: $ref_sha (type: $ref_type)"
  
  if [ "$ref_type" = "tag" ]; then
    # Annotated tag - dereference to commit
    local commit_sha
    commit_sha=$(gh api "repos/${owner_repo}/git/tags/${ref_sha}" --jq '.object.sha' 2>/dev/null)
    echo "Dereferenced commit SHA: $commit_sha"
  else
    echo "Lightweight tag, commit SHA = $ref_sha"
  fi
}

echo "=== azure/login v3.0.0 ==="
dereference_tag "azure/login" "v3.0.0"

echo ""
echo "=== golangci/golangci-lint-action v9.2.1 ==="
dereference_tag "golangci/golangci-lint-action" "v9.2.1"

echo ""
echo "=== github/codeql-action v4.36.0 ==="
dereference_tag "github/codeql-action" "v4.36.0"

echo ""
echo "=== codecov/codecov-action v6.0.1 ==="
dereference_tag "codecov/codecov-action" "v6.0.1"

echo ""
echo "=== securego/gosec v2.26.1 ==="
dereference_tag "securego/gosec" "v2.26.1"

Length of output: 842


@cristim All 18 SHA pins have been independently verified. The apparent mismatches from my first pass were caused by annotated tag object SHAs being returned by the git/ref/tags API — after dereferencing each annotated tag to its underlying commit SHA, every entry in your correction table checks out:

Action Claimed Verified commit SHA ✓
azure/login v3.0.0 532459ea 532459ea530d8321f... ✅
golangci/golangci-lint-action v9.2.1 82606bf2 82606bf257cbaff2... ✅
github/codeql-action v4.36.0 7211b7c8 7211b7c8077ea37d... ✅
codecov/codecov-action v6.0.1 e79a6962 e79a6962e0d4c0c1... ✅
securego/gosec v2.26.1 4a3bd8af 4a3bd8af174872c7... ✅

All other 13 pins matched on the first pass. The full set of 18 corrected SHA pins is accurate. Triggering the incremental review now.

(╯°□°)╯ 🐇 ✓

✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim
cristim merged commit 5441f9e into feat/multicloud-web-frontend May 22, 2026
5 checks passed
@cristim
cristim deleted the sec/ci-sha-pins branch June 3, 2026 21:55
cristim added a commit that referenced this pull request Sep 27, 2026
* sec(ci): pin all GitHub Actions to commit SHAs (#415)

Replace all `uses: org/action@tag` refs across every workflow file
with `uses: org/action@<sha> # tag` pins. Several workflows referenced
non-existent future versions (v5/v6/v7 for actions still on v4); these
are corrected to the actual latest released tag while being SHA-pinned.

Closes #415

* fix(ci): disable credential persistence on all checkout steps

All 11 actions/checkout uses defaulted to persist-credentials: true,
leaving the GitHub token in git config after checkout. None of these jobs
need persisted credentials for authenticated git operations. Set
persist-credentials: false on every step to reduce the token exposure
window.

Fixes CodeRabbit finding (artipacked) on PR #536.

* fix(ci): disable credential persistence in rollback and database-migration

All 5 actions/checkout steps in rollback.yml and all 4 in
database-migration.yml defaulted to persist-credentials: true, leaving
the GitHub token in git config for the remainder of each job. Neither
workflow has any step that performs authenticated git operations after
checkout (cloud auth is done via dedicated aws-actions/configure-aws-credentials,
google-github-actions/auth, and azure/login actions). Setting
persist-credentials: false on every checkout step closes the token
exposure window.

Fixes remaining CodeRabbit artipacked findings on PR #536 (nitpick
comments on rollback.yml and database-migration.yml).

* fix(ci): pin actions to latest SHA of the in-use major, not a downgraded major

The previous SHA-pin commit resolved each action to a commit in an older
major version than the workflows were using (e.g. checkout pinned to v4.3.1
while the branch used v5, configure-aws-credentials pinned to v4.3.1 while
the branch used v6, etc.). This corrects every pin to the latest release
within the same major that the base branch (feat/multicloud-web-frontend)
was already on. No logic changes; SHA + version comment only.

Actions corrected (old major -> correct major):
  actions/checkout              v4.3.1 -> v5.0.1    (34 occurrences)
  actions/download-artifact     v4.3.0 -> v7.0.0     (4 occurrences)
  actions/upload-artifact       v4.6.2 -> v6.0.0     (9 occurrences)
  actions/setup-go              v5.6.0 -> v6.4.0     (8 occurrences)
  actions/setup-node            v4.4.0 -> v6.4.0     (3 occurrences)
  actions/setup-python          v5.6.0 -> v6.2.0     (1 occurrence)
  aws-actions/configure-aws-credentials  v4.3.1 -> v6.1.1  (10 occurrences; standardises ALL to v6.1.1)
  azure/login                   v2.3.0 -> v3.0.0     (7 occurrences)
  docker/build-push-action      v6.9.0 -> v7.2.0     (1 occurrence)
  docker/setup-buildx-action    v3.9.0 -> v4.0.0     (2 occurrences)
  google-github-actions/auth    v2.1.9 -> v3.0.0     (5 occurrences)
  google-github-actions/setup-gcloud  v2.2.1 -> v3.0.1  (2 occurrences)
  hashicorp/setup-terraform     v3.1.2 -> v4.0.1     (15 occurrences)
  codecov/codecov-action        v5.5.4 -> v6.0.1     (1 occurrence)
  golangci/golangci-lint-action v6.5.2 -> v9.2.1     (1 occurrence)
  snyk/actions/golang           v1.0.0 -> 0.4.0      (1 occurrence; base was on 0.x)
  securego/gosec                v2.22.9 -> v2.26.1   (1 occurrence; updated to latest v2)
  github/codeql-action          v4.35.5 -> v4.36.0   (2 occurrences; updated to latest v4)

All 23 SHAs independently verified against their tags via GitHub API.
No float tags remain. YAML validates on all 15 files.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/m Days impact/internal Team-internal only priority/p2 Backlog-worthy severity/medium Moderate harm triaged Item has been triaged type/security Security finding urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant