-
-
Notifications
You must be signed in to change notification settings - Fork 0
fix(ci): pin third-party actions to full commit SHAs #158
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -20,10 +20,10 @@ jobs: | |
| trufflehog: | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v7.0.1 | ||
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
| with: | ||
| fetch-depth: 0 | ||
| - name: TruffleHog Secret Scan | ||
| uses: trufflesecurity/trufflehog@main | ||
| uses: trufflesecurity/trufflehog@288a8a8643a2c5a36b81d231c550dccfa0beeb64 # main | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📐 Maintainability & Code Quality | 🛡️ Analyzed with Security Review | 🟡 Minor | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: rg -n 'actions\.lock|pinact|trufflehog|288a8a8643a2c5a36b81d231c550dccfa0beeb64|5a6944e878348ba138c91a3715477d85341e206d' .github Makefile* package.json pyproject.toml Cargo.toml 2>/dev/null
sed -n '1,130p' .github/workflows/actions.lock
sed -n '1,60p' .github/workflows/secret-scanner.ymlRepository: hyperpolymath/universal-chat-extractor Length of output: 5802 🏁 Script executed: #!/bin/bash
set -u
printf '%s\n' '--- repository contract references ---'
rg -n -i 'gh actions-lock|actions-lock|actions\.lock|lockfile' .github Makefile* package.json pyproject.toml Cargo.toml README* 2>/dev/null || true
printf '%s\n' '--- TruffleHog commit metadata ---'
for endpoint in \
'https://api.github.com/repos/trufflesecurity/trufflehog/commits/288a8a8643a2c5a36b81d231c550dccfa0beeb64' \
'https://api.github.com/repos/trufflesecurity/trufflehog/git/ref/heads/main' \
'https://api.github.com/repos/trufflesecurity/trufflehog/commits/5a6944e878348ba138c91a3715477d85341e206d'
do
printf '\n%s\n' "$endpoint"
curl -L --fail --silent --show-error \
-H 'Accept: application/vnd.github+json' \
"$endpoint" |
python3 -c 'import json,sys; d=json.load(sys.stdin); print(json.dumps({k:d.get(k) for k in ("sha","ref","object","html_url","message","commit") if k in d}, sort_keys=True, default=str))' ||
true
doneRepository: hyperpolymath/universal-chat-extractor Length of output: 7122 Regenerate the generated action lockfile.
🤖 Prompt for AI Agents |
||
| with: | ||
| extra_args: --only-verified --fail | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Include the original
v0.3.0ref in the trailing comment.The SHA matches
.github/workflows/actions.lock, but the comment only identifies the lockfile authority. Add# v0.3.0while retaining theNOSONARnote so the pin remains traceable to the intended release.🤖 Prompt for AI Agents