Skip to content

F505911: Pin GitHub Actions to commit SHAs in the publish workflows - #25

Merged
mblode merged 1 commit into
masterfrom
f505911-pin-github-actions-to-commit-shas-in-the
Oct 4, 2026
Merged

mblode merged 1 commit into
masterfrom
f505911-pin-github-actions-to-commit-shas-in-the

Conversation

@mblode

@mblode mblode commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Summary

  • Pins every uses: in .github/workflows/ci.yml and .github/workflows/npm-publish.yml to a full 40-character commit SHA, with a # vX.Y.Z comment for readability.
  • npm-publish.yml has contents: write and id-token: write; it previously pulled actions/checkout, actions/setup-node, and changesets/action by a movable tag, so a compromised/moved tag could run arbitrary code during a publish with those permissions. Pinning to a SHA removes that risk.
  • Resolved SHAs (via gh api repos/<org>/<repo>/commits/<tag>), kept on the same major version already in use:
    • actions/checkout@11d5960a326750d5838078e36cf38b85af677262 (v4.4.0)
    • actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 (v4.4.0)
    • changesets/action@a45c4d594aa4e2c509dc14a9f2b3b67ba3780d0d (v1.9.0)

Decisions for the reviewer

  • Kept the existing major versions (v4 for checkout/setup-node, v1 for changesets/action) rather than upgrading majors, to avoid unrelated behavior changes in this security fix.

Test plan

  • npm test (lint, format:check, check:types, test:unit, build, publint, check:exports) passes locally.
  • git diff confirms dist/ is unchanged by the build (only the .map churned, which is expected per AGENTS.md and excluded from the commit).
  • CI passes on this PR.

Learned: the worktree's node_modules for lightningcss-cli/esbuild had their postinstall scripts blocked by the sandbox's allowScripts gate; ran their install scripts directly rather than editing package.json's allowScripts, so the workflow-only diff stayed clean.

🤖 Generated with Claude Code

https://claude.ai/code/session_017xivnFFxtKVFiyV9LCGX9z

npm-publish.yml carries contents: write and id-token: write alongside
tag-pinned actions, so a moved tag could run arbitrary code during a
publish. Pin every uses: in ci.yml and npm-publish.yml to a full commit
SHA with a version comment.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017xivnFFxtKVFiyV9LCGX9z
@vercel

vercel Bot commented Oct 4, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
burger Ignored Ignored Oct 4, 2026 7:28am UTC

Request Review

@mblode
mblode marked this pull request as ready for review October 4, 2026 07:29
@mblode

mblode commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author
Verdict: pass. No proof command configured in this repo (no npm run verify). All five uses: in ci.yml and npm-publish.yml pinned to full 40-char commit SHAs with version comments; npm test passes locally (lint, format, types, unit, build, publint, check:exports); dist unaffected.

@mblode

mblode commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Review current commit 9d7c2c7665c530fd019e9017d6ebc4cb62a3911f.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T07:31:10.518885Z 9d7c2c7 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. You're on a roll.

Reviewed commit: 9d7c2c7665

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mblode
mblode merged commit e4cadd7 into master Oct 4, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant