Skip to content

Commit 2a6e55d

Browse files
🛡️ Sentinel: Fix moving and non-existent version tags in GitHub Actions workflows by pinning to secure, immutable commit SHAs.
- Pin actions/checkout to immutable SHA of v4.4.0 - Pin jdx/mise-action to immutable SHA of v4.2.4 - Document the learning in the Sentinel security journal
1 parent 6bb7557 commit 2a6e55d

3 files changed

Lines changed: 9 additions & 4 deletions

File tree

‎.github/workflows/check.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,8 @@ jobs:
1414
- "3.13"
1515
- "3.12"
1616
steps:
17-
- uses: actions/checkout@v7
18-
- uses: jdx/mise-action@v4
17+
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
18+
- uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
1919
with:
2020
tool_versions: |
2121
python ${{ matrix.python-version }}

‎.github/workflows/docs.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,8 @@ jobs:
1010
deploy:
1111
runs-on: ubuntu-latest
1212
steps:
13-
- uses: actions/checkout@v7
14-
- uses: jdx/mise-action@v4
13+
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
14+
- uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
1515
- name: Configure Git Credentials
1616
run: |
1717
git config user.name github-actions[bot]

‎.jules/sentinel.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,8 @@
11
# Sentinel Security Journal
22

33
This journal contains critical security learnings specific to this project.
4+
5+
## 2026-03-10 - Secure GitHub Actions Pinned to Immutable SHAs
6+
**Vulnerability:** Workflows were referencing a non-existent version tag `actions/checkout@v7` and a mutable major version tag `jdx/mise-action@v4`. Using non-existent or moving tags exposes the repository to supply chain and tag-spoofing attacks if an attacker registers or hijacks the version tag.
7+
**Learning:** Third-party actions should not rely on moving major version tags or non-existent tags. Moving tags are mutable, and their associated commits can change, potentially introducing untested or malicious code.
8+
**Prevention:** Pin all third-party GitHub Actions to secure, immutable 40-character full-length commit SHAs, and append a comment indicating the human-readable version (e.g. `# v4.4.0`). Dependabot can then be configured to automatically update these SHAs.

0 commit comments

Comments
 (0)