diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4f6ee6b..1f85f28 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -76,12 +76,26 @@ jobs: fetch-depth: 0 - name: Scan for committed secrets - # Pinned to a release tag. Never use @master or @main for a third-party - # action: a mutable ref is a remote-code-execution path into CI. - # Dependabot keeps this pin current (.github/dependabot.yml). + # Two pins, not one. `uses:` pins the composite wrapper; `version:` pins + # the scanner the wrapper actually runs. The action's `version` input + # defaults to `latest`, so without the second pin this step downloads + # ghcr.io/trufflesecurity/trufflehog:latest on every run — the code that + # decides whether the job passes would be a mutable ref, which is the + # remote-code-execution path this comment used to claim was closed. It + # also meant an upstream change to exit-code behaviour reached this + # workflow with no pull request. Keep the two versions equal. + # + # Dependabot updates the `uses:` ref (.github/dependabot.yml); it does + # not know about `version:`. Update both together. See issue #14. + # + # Mind the prefix: the action is tagged `v3.96.0`, the container image is + # tagged `3.96.0`. Passing the `v` form here fails the job with + # `manifest unknown` and exit 125 — noisy, but fail-closed, which is the + # right direction for a security gate. uses: trufflesecurity/trufflehog@v3.96.0 with: path: ./ + version: 3.96.0 # --only-verified keeps this a blocking gate rather than a noise # generator: it fails on credentials TruffleHog can actively confirm # are live. Unverified matches are deliberately not fatal, because