Skip to content

Verify the upstream signature on every run and add zizmor and cargo-deny - #9

Merged
LucaCappelletti94 merged 1 commit into
mainfrom
upstream/ci-supply-chain
Sep 30, 2026
Merged

LucaCappelletti94 merged 1 commit into
mainfrom
upstream/ci-supply-chain

Conversation

@LucaCappelletti94

Copy link
Copy Markdown
Owner

The weekly check that the vendored files match the release only compared the archive against the committed checksum. The Sigstore signature on SQLite3MC's SHA256SUMS was checked once, when the release bot moved the pin, so a commit that changed both the bytes and the checksum would have passed every later run. The signing identity is now defined once and shared by the bump and re-vendor scripts, and the pinned checksum counts only while the signed SHA256SUMS lists it. That job therefore re-proves the signature on every run under its existing check name.

zizmor now checks the workflows, online so it can spot impostor commits and actions with known vulnerabilities. Its first run asked for checkouts that drop their credentials and a week of Dependabot cooldown, and both are in. It also wants the new $/ form for the release workflow's call into CI, which actionlint cannot parse yet (rhysd/actionlint#711), so that one finding is ignored with its reason written beside it. A new required job runs cargo-deny over the two test crates for advisories, licences, duplicate versions and sources, dev-dependencies included since the Wasm crate has no others. Dependabot alerts and security updates were switched on in the repository settings alongside this.

sqlcipher-src already re-checks its GPG signatures on every run, but it lacks zizmor, cargo-deny and Dependabot alerts and security updates, so it should get the same change.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: LucaCappelletti94/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 9ca11d3f-cc11-4bf1-bc08-ef0c8283b121

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

Copy link
Copy Markdown

@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (131f683) to head (3c35837).

Additional details and impacted files
@@            Coverage Diff            @@
##              main        #9   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files            1         1           
  Lines            3         3           
  Branches         3         3           
=========================================
  Hits             3         3           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@LucaCappelletti94
LucaCappelletti94 merged commit 2e8b059 into main Sep 30, 2026
20 checks passed
@LucaCappelletti94
LucaCappelletti94 deleted the upstream/ci-supply-chain branch September 30, 2026 15:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant