Reviewing 7 commits since 2026-07-18 (f5939b7..501ff7b). Findings here focus on SDLC and workflow changes — Dependabot, GitHub Code Scanning, and Renovate handle the rest. Tick the box once the underlying issue is resolved or recorded in SECURITY.md.
How to respond
Preferred flow — tick the boxes on the findings you want broken out, then comment:
@last-light create issues — files one issue per ticked finding (default)
Other shortcuts:
@last-light create issues for the criticals — every Critical finding (ticked or not)
@last-light create issues for the highs — same, for High
@last-light create issues for items 1, 3, 5 — specific items by number (1-based, top to bottom)
@last-light create issues for all — every finding in this scan
@last-light accept-risk for item N: <reason> — suppress this finding in future scans
@last-light false-positive for item N: <reason> — suppress this finding in future scans
- Comment freely to ask questions or discuss
Summary
| Severity |
Count |
| Critical |
0 |
| High |
1 |
| Medium |
0 |
| Low |
0 |
| Total |
1 |
Suppressed by SECURITY.md: 0 (accepted: 0, false-positives: 0). Below severity floor: 0.
Commits reviewed: f5939b7 feat: upgrade to commitlint v21 on node 24, 62fc820 ci: smoke test the published image instead of pulling it in PRs, bc4f569 ci: pin actions to SHAs and drop excess permissions, 31e5e04 Merge pull request #1 from yo61/feat/commitlint-v21, fae6c5c fix: pin the runtime image by digest, not tag, d365636 ci: run the action from the published image again, 501ff7b Merge pull request #2 from yo61/chore/pin-image-by-digest
Findings
🔴 Critical (0)
No findings.
🟠 High (1)
Details
FROM node:24.19.0-alpine3.24
RUN apk --no-cache add git
COPY --from=build dist/run.mjs /run.mjs
COPY package*.json /
RUN npm ci --production --ignore-scripts
COPY entrypoint.sh /entrypoint.sh
ENTRYPOINT ["/entrypoint.sh"]
The runtime stage declares no USER, so the entrypoint runs as root. This action executes git and commitlint against commit data from pull requests; a vulnerability or malformed input that escaped the linter would run with root privileges inside the container, widening any escape or filesystem write. The hardening landed in this window (SHA-pinned actions, dropped permissions, digest-pinned image) did not address the container's own privilege level.
Suggested fix: create a non-root user in the runtime stage and switch to it, e.g. add after the final FROM:
RUN addgroup -S app && adduser -S -G app app
USER app
Ensure entrypoint.sh and the copied files are readable/executable by that user. If a step genuinely needs root, scope it to a separate stage and drop privileges before ENTRYPOINT.
🟡 Medium (0)
No findings.
🟢 Low (0)
No findings.
Reviewing 7 commits since 2026-07-18 (f5939b7..501ff7b). Findings here focus on SDLC and workflow changes — Dependabot, GitHub Code Scanning, and Renovate handle the rest. Tick the box once the underlying issue is resolved or recorded in
SECURITY.md.How to respond
Preferred flow — tick the boxes on the findings you want broken out, then comment:
@last-light create issues— files one issue per ticked finding (default)Other shortcuts:
@last-light create issues for the criticals— every Critical finding (ticked or not)@last-light create issues for the highs— same, for High@last-light create issues for items 1, 3, 5— specific items by number (1-based, top to bottom)@last-light create issues for all— every finding in this scan@last-light accept-risk for item N: <reason>— suppress this finding in future scans@last-light false-positive for item N: <reason>— suppress this finding in future scansSummary
Suppressed by
SECURITY.md: 0 (accepted: 0, false-positives: 0). Below severity floor: 0.Findings
🔴 Critical (0)
No findings.
🟠 High (1)
Dockerfile:23(semgrep ·dockerfile.security.missing-user-entrypoint.missing-user-entrypoint)Details
The runtime stage declares no
USER, so the entrypoint runs asroot. This action executesgitand commitlint against commit data from pull requests; a vulnerability or malformed input that escaped the linter would run with root privileges inside the container, widening any escape or filesystem write. The hardening landed in this window (SHA-pinned actions, dropped permissions, digest-pinned image) did not address the container's own privilege level.Suggested fix: create a non-root user in the runtime stage and switch to it, e.g. add after the final
FROM:Ensure
entrypoint.shand the copied files are readable/executable by that user. If a step genuinely needs root, scope it to a separate stage and drop privileges beforeENTRYPOINT.🟡 Medium (0)
No findings.
🟢 Low (0)
No findings.