Skip to content

sec(ci): install golang-migrate via module-hash-pinned go install instead of unverified tarball (closes #434) - #537

Merged
cristim merged 2 commits into
feat/multicloud-web-frontendfrom
sec/ci-migrate-verify
Jun 5, 2026
Merged

cristim merged 2 commits into
feat/multicloud-web-frontendfrom
sec/ci-migrate-verify

Conversation

@cristim

@cristim cristim commented May 20, 2026 •

Copy link
Copy Markdown
Member

Closes #434.

Replaces the unverified curl -L .../migrate.linux-amd64.tar.gz | tar xvz install of golang-migrate (RCE / supply-chain risk on runners holding DB passwords + cloud creds) with:

  • actions/setup-go@v5 (go-version-file: go.mod), then
  • go install -tags 'postgres' github.com/golang-migrate/migrate/v4/cmd/migrate@v4.19.1

in all three (AWS/GCP/Azure) migration jobs. Integrity is enforced by the Go toolchain via go.sum (module hash pinned: h1:OCyb44lFuQfYXYLx1SCxPZQGU7mcaZ7gH9yH4jSFbBA=) + GOSUMDB, which fails closed on mismatch. Version is pinned to @v4.19.1 (no @latest), matching the approach already used in ci.yml. This is issue #434's option (b) (module-hash-pinned go install), which is at least as strong as the tarball-sha256 option and consistent with existing CI.

Note: bumps golang-migrate v4.17.0 -> v4.19.1.

(PR title/body corrected to match the actual implementation: an earlier draft described a tarball-sha256-verify approach that was not what landed.)

Replace the unverified `curl | tar` pipe with a two-step download + sha256
verification before extraction. The official sha256sum.txt published with
the v4.17.0 release is used as the source of truth. `set -euo pipefail`
ensures the step aborts immediately if the checksum check fails.

Closes #434
@cristim cristim added triaged Item has been triaged priority/p2 Backlog-worthy severity/medium Moderate harm urgency/this-sprint Within the current sprint impact/internal Team-internal only effort/xs Trivial / one-liner type/security Security finding labels May 20, 2026
@coderabbitai

coderabbitai Bot commented May 20, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@cristim, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 51 minutes and 23 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 62f029a5-78d4-4d92-a1bf-4b22c1c34978

📥 Commits

Reviewing files that changed from the base of the PR and between 1b494d4 and ece1b9d.

📒 Files selected for processing (1)
  • .github/workflows/database-migration.yml
📝 Walkthrough

Walkthrough

The workflow file .github/workflows/database-migration.yml updates golang-migrate installation across three cloud provider jobs (AWS, GCP, Azure) to download the binary with pinned version and SHA-256 checksum verification instead of unsecured direct piping from curl to tar.

Changes

golang-migrate Download Security Hardening

Layer / File(s) Summary
Add SHA256 checksum verification to all provider jobs
.github/workflows/database-migration.yml
AWS, GCP, and Azure jobs each now pin MIGRATE_VERSION and MIGRATE_SHA256, download the tarball to a temporary file, verify the checksum strictly before extraction, and install via sudo install with cleanup. Shell safety flags set -euo pipefail are added to each block, replacing the prior unsecured curl-to-tar pipeline.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Suggested labels

priority/p0, severity/high, urgency/now

Poem

🐰 A rabbit hops through CI with care,
No more blind downloads through the air!
SHA checksums now guard the way,
golang-migrate verified each day.
Security hopping, strong and true! ✓

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately reflects the main security change: adding SHA-256 verification before installing golang-migrate, which directly addresses the PR's core objective.
Linked Issues check ✅ Passed All coding requirements from issue #434 are met: SHA-256 checksum verification is implemented, the tarball is verified before extraction, and proper error handling with set -euo pipefail is included.
Out of Scope Changes check ✅ Passed All changes are directly scoped to the three golang-migrate installation steps in .github/workflows/database-migration.yml with no extraneous modifications.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch sec/ci-migrate-verify

Comment @coderabbitai help to get the list of available commands and usage tips.

@cristim

cristim commented May 20, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 20, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented May 20, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 20, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
.github/workflows/database-migration.yml (1)

147-157: ⚖️ Poor tradeoff

Consider extracting the golang-migrate installation into a composite action or using go install for better maintainability.

The installation logic is duplicated identically across all three cloud provider jobs (AWS, GCP, Azure). While the current approach significantly improves security, the duplication creates a maintenance burden—any version bump or checksum update must be applied in three places.

Two alternatives to consider:

  1. Extract to a composite action: Create .github/actions/install-golang-migrate/action.yml that accepts version and SHA256 as inputs, reducing duplication and centralizing the installation logic.

  2. Use go install (preferred): As suggested in issue #434, install via a pinned Go module eliminates tarball/checksum management entirely:

    - name: Install golang-migrate
      run: |
        go install -tags 'postgres' github.com/golang-migrate/migrate/v4/cmd/migrate@v4.17.0

    This leverages Go's module checksums (go.sum) for integrity verification and is already used elsewhere in your CI.

Also applies to: 226-236, 295-305

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/database-migration.yml around lines 147 - 157, The
golang-migrate install block (env MIGRATE_VERSION / MIGRATE_SHA256 and the run:
curl|sha256sum|tar|sudo install sequence) is duplicated across provider jobs;
replace it by either (A) extracting that logic into a composite action (e.g.,
.github/actions/install-golang-migrate/action.yml) that accepts MIGRATE_VERSION
and MIGRATE_SHA256 inputs and performs the curl/verify/install steps, then call
that action from each job; or (B, preferred) remove the tarball steps and
replace the run block with a go install invocation that pins the module (e.g.,
go install -tags 'postgres'
github.com/golang-migrate/migrate/v4/cmd/migrate@${MIGRATE_VERSION}) so CI
relies on Go module checksums instead of manual tarball download; update the
three occurrences (the run blocks referenced) accordingly.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In @.github/workflows/database-migration.yml:
- Around line 147-157: The golang-migrate install block (env MIGRATE_VERSION /
MIGRATE_SHA256 and the run: curl|sha256sum|tar|sudo install sequence) is
duplicated across provider jobs; replace it by either (A) extracting that logic
into a composite action (e.g.,
.github/actions/install-golang-migrate/action.yml) that accepts MIGRATE_VERSION
and MIGRATE_SHA256 inputs and performs the curl/verify/install steps, then call
that action from each job; or (B, preferred) remove the tarball steps and
replace the run block with a go install invocation that pins the module (e.g.,
go install -tags 'postgres'
github.com/golang-migrate/migrate/v4/cmd/migrate@${MIGRATE_VERSION}) so CI
relies on Go module checksums instead of manual tarball download; update the
three occurrences (the run blocks referenced) accordingly.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3e514ebd-e240-411f-9558-8512c96a3c66

📥 Commits

Reviewing files that changed from the base of the PR and between b1ea4b1 and 1b494d4.

📒 Files selected for processing (1)
  • .github/workflows/database-migration.yml

…nstall

All three cloud provider jobs in database-migration.yml had identical
curl/sha256/tar/install blocks. Replaced each with setup-go + go install
using the version already pinned in go.mod (v4.19.1), leveraging Go
module checksums for integrity and eliminating the manual tarball approach.
@cristim

cristim commented Jun 1, 2026

Copy link
Copy Markdown
Member Author

Addressed the duplicated golang-migrate installation in ece1b9d: replaced all three identical curl/sha256/tar/install blocks with setup-go + go install -tags 'postgres' github.com/golang-migrate/migrate/v4/cmd/migrate@v4.19.1 (the version already in go.mod), relying on Go module checksums for integrity. @coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
cat .github/workflows/database-migration.yml

Length of output: 12612



@cristim The updated approach looks excellent and is a clear improvement over both the original insecure curl | tar pattern and even the initial sha256-verification approach.

A few observations from the review:

✅ What's well done:

  • go install with an explicit @v4.19.1 version tag is properly pinned.
  • Integrity is enforced by the Go checksum database (sum.golang.org) and the repo's go.sum — this is cryptographically stronger than verifying a pre-built binary's sha256, since it verifies the module source rather than a distribution artifact.
  • -tags 'postgres' is correctly included so the postgres driver is compiled in.
  • go-version-file: go.mod pins the Go toolchain version consistently with the rest of the project.
  • All three jobs are now symmetric — no more divergence risk.

Minor note (non-blocking):
The Set up Go + Install golang-migrate steps are still repeated verbatim in all three jobs. This is unavoidable without a composite action or reusable workflow, and is entirely reasonable for this use case.

One thing to verify (if not already done): confirm that go.sum in the repo has an entry for github.com/golang-migrate/migrate/v4 v4.19.1, so go install resolves against the checked-in checksum rather than fetching it fresh each time. If the module isn't already in go.sum, you may want to run go get github.com/golang-migrate/migrate/v4/cmd/migrate@v4.19.1 locally and commit the updated go.sum.

Overall the PR is in great shape — this is the cleaner of the two alternatives from #434. 🐇

✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented Jun 1, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented Jun 1, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented Jun 4, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 4, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim
cristim merged commit 657e6fd into feat/multicloud-web-frontend Jun 5, 2026
4 checks passed
@cristim cristim changed the title sec(ci): verify golang-migrate tarball sha256 before install sec(ci): install golang-migrate via module-hash-pinned go install instead of unverified tarball (closes #434) Jun 5, 2026
@cristim
cristim deleted the sec/ci-migrate-verify branch July 27, 2026 11:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/xs Trivial / one-liner impact/internal Team-internal only priority/p2 Backlog-worthy severity/medium Moderate harm triaged Item has been triaged type/security Security finding urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant