Skip to content

chore(ci): pin actions to commit SHAs and lint workflows with zizmor - #135

Merged
giraffesyo merged 1 commit into
canaryfrom
chore/harden-ci
Oct 3, 2026
Merged

giraffesyo merged 1 commit into
canaryfrom
chore/harden-ci

Conversation

@giraffesyo

Copy link
Copy Markdown
Member

What changed

  • Every uses: is pinned to the commit SHA of the newest release in its current major, with the version in a trailing comment. Dependabot keeps bumping them.
  • Every checkout sets persist-credentials: false.
  • release-please.yml: workflow permissions are {}, with contents: write and pull-requests: write on the job only. It has a 10 minute timeout and a concurrency group that queues runs.
  • New workflows job in ci.yml runs zizmor and fails on findings.
  • govulncheck is installed at v1.8.0 instead of @latest. The vulnerability database is still fetched live. Dependabot does not bump this pin.
  • Dependabot waits 7 days after a release before proposing it, for both ecosystems.
  • CodeQL job drops actions: read, which is only needed on private repos.

Why

zizmor reported 16 high severity findings on the old workflows, mostly unpinned actions and workflow-level write permissions. It reports none now, and actionlint passes.

The repo now requires SHA-pinned actions, so the workflows on canary fail until this merges.

Every action is pinned to a commit SHA and checkouts no longer persist
the token. release-please gets its write permissions on the job only,
plus a timeout and a concurrency group. A new workflows job runs zizmor
so these rules stay enforced. govulncheck is installed at a fixed
version, and Dependabot waits 7 days before proposing a new release.
@giraffesyo
giraffesyo merged commit 3aae49d into canary Oct 3, 2026
8 checks passed
@giraffesyo
giraffesyo deleted the chore/harden-ci branch October 3, 2026 03:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant