[LOW] security(ci): pin actions to immutable revisions - #1143
OskarEichler wants to merge 2 commits into
Conversation
|
@OskarEichler is attempting to deploy a commit to the Nearform Team on Vercel. A member of the Team first needs to authorize it. |
|
|
|
||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 |
There was a problem hiding this comment.
At this point it would be worth to upgrade them to their latest version
|
Upgraded the pins in 578d1a2 to the latest stable releases: checkout v7.0.1, setup-node v7.0.0, and changesets/action v2.1.2. Resolved each release tag to its commit and checked the action manifests; all use the Node 24 action runtime on the hosted ubuntu-latest runner. The application Node version and existing workflow commands remain unchanged. YAML and diff checks pass; I did not execute the privileged publishing workflow. |
Security impact
The pull-request and package-release workflows execute actions/checkout@v4, actions/setup-node@v4, and changesets/action@v1 through mutable major-version references. If one of those references is moved or its publishing account is compromised, unreviewed code can execute in CI. The release job has repository write access and npm trusted-publishing access, so immutable action identity matters at that boundary.
Fix
Pin every external action invocation to the exact commit currently selected by its existing major reference, retaining a version comment for update tooling and reviewers:
This does not upgrade action majors or change workflow behavior. Token permissions and the floating npm install are separate focused changes.
Verification
No runtime package changes or changeset are needed for CI-only hardening.