Verify the upstream signature on every run and add zizmor and cargo-deny - #9
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Repository: LucaCappelletti94/coderabbit/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #9 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 1 1
Lines 3 3
Branches 3 3
=========================================
Hits 3 3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|



The weekly check that the vendored files match the release only compared the archive against the committed checksum. The Sigstore signature on SQLite3MC's
SHA256SUMSwas checked once, when the release bot moved the pin, so a commit that changed both the bytes and the checksum would have passed every later run. The signing identity is now defined once and shared by the bump and re-vendor scripts, and the pinned checksum counts only while the signedSHA256SUMSlists it. That job therefore re-proves the signature on every run under its existing check name.zizmor now checks the workflows, online so it can spot impostor commits and actions with known vulnerabilities. Its first run asked for checkouts that drop their credentials and a week of Dependabot cooldown, and both are in. It also wants the new
$/form for the release workflow's call into CI, which actionlint cannot parse yet (rhysd/actionlint#711), so that one finding is ignored with its reason written beside it. A new required job runs cargo-deny over the two test crates for advisories, licences, duplicate versions and sources, dev-dependencies included since the Wasm crate has no others. Dependabot alerts and security updates were switched on in the repository settings alongside this.sqlcipher-src already re-checks its GPG signatures on every run, but it lacks zizmor, cargo-deny and Dependabot alerts and security updates, so it should get the same change.