Skip to content

Pin workflow actions to commit SHAs and configure Dependabot - #11

Merged
Commanderx-code merged 1 commit into
mainfrom
ci/harden-supply-chain
Sep 25, 2026
Merged

Commanderx-code merged 1 commit into
mainfrom
ci/harden-supply-chain

Conversation

@Commanderx-code

Copy link
Copy Markdown
Owner

Change

Pins every GitHub Action to a commit SHA. Tags like actions/checkout@v4 can be moved. If one of these actions were compromised, the moved tag would run the attacker's code in the job that builds and uploads release packages. All 17 uses: lines now pin the exact commit that each tag points to today, so CI runs the same code as before:

Action Pinned to
actions/checkout 11d5960 (v4.4.0)
actions/setup-node 49933ea (v4.4.0)
actions/upload-artifact ea165f8 (v4.6.2)
actions/download-artifact d3f86a1 (v4.3.0)
dtolnay/rust-toolchain 6bed076 (head of its stable branch)

rust-toolchain picks its Rust version from the branch you reference. Its steps now pass toolchain: stable explicitly, so a later pin update can't change the Rust version.

Adds .github/dependabot.yml. Dependabot will open grouped weekly update PRs every Monday:

  • GitHub Actions: it moves the pinned SHAs and their version comments.
  • npm and Cargo: minor and patch updates are grouped into one PR per ecosystem; major updates arrive separately.
  • linutil_core is excluded. Its revision must match REVISION in src-tauri/src/toolbox.rs, and scripts/pin-toolbox.mjs updates the two together.

Security updates were already enabled in the repository settings and are unchanged.

Updates docs/development.md to describe how actions are pinned and how Dependabot is configured.

Validation

  • Each pin was resolved through the GitHub API. Each v4 tag currently points at the pinned commit, so behaviour is unchanged.
  • Before pinning rust-toolchain, I checked that its action.yml at 6bed076 defaults to stable.
  • Both workflow files and dependabot.yml parse as YAML. No unpinned uses: remain.
  • npm run check: passed.
  • This PR's own CI run uses the pinned actions in every job, including the build, the install tests and the audits.

Review notes

  • Expect Dependabot PRs every Monday, one group per ecosystem. They must pass the 9 required checks and the CodeQL rule before they can merge.
  • For an Action update, check the linked release notes before merging. Its SHA pins a different version of code that runs in CI.

🤖 Generated with Claude Code

Actions referenced by a movable tag (actions/checkout@v4) run whatever the
tag points to, including in the job that builds release packages. Every
action is now pinned to the commit its tag resolves to today, so CI runs
the same code, with the version in a trailing comment. rust-toolchain now
names its toolchain explicitly so a moved pin cannot change it.

dependabot.yml opens grouped weekly updates for Actions, npm and Cargo.
The Commander Toolbox pin is excluded because it must match REVISION in
toolbox.rs and is updated with scripts/pin-toolbox.mjs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Commanderx-code
Commanderx-code merged commit 42c166d into main Sep 25, 2026
14 checks passed
@Commanderx-code
Commanderx-code deleted the ci/harden-supply-chain branch September 25, 2026 17:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant