Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/auto-merge-dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ jobs:
steps:
- name: Fetch Dependabot metadata
id: metadata
uses: dependabot/fetch-metadata@v2
uses: dependabot/fetch-metadata@v3

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🔴 Critical | ⚡ Quick win

Security Misconfiguration (CWE-494): Download of Code Without Integrity Check

Reachability: External

Pin every upgraded action to an immutable commit SHA. Mutable tags allow action code to change without a workflow diff; this is especially dangerous in .github/workflows/auto-merge-dependabot.yml, which runs under write permissions.

  • .github/workflows/auto-merge-dependabot.yml#L18-L18: pin dependabot/fetch-metadata.
  • .github/workflows/ci.yml#L12-L18: pin checkout, pnpm setup, and setup-node.
  • .github/workflows/ci.yml#L45-L56: pin checkout and all CodeQL actions.
  • .github/workflows/playwright.yml#L12-L13: pin checkout and setup-node.
  • .github/workflows/playwright.yml#L22-L22: pin upload-artifact.
🧰 Tools
🪛 zizmor (1.26.1)

[error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

📍 Affects 3 files
  • .github/workflows/auto-merge-dependabot.yml#L18-L18 (this comment)
  • .github/workflows/ci.yml#L12-L18
  • .github/workflows/ci.yml#L45-L56
  • .github/workflows/playwright.yml#L12-L13
  • .github/workflows/playwright.yml#L22-L22
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/auto-merge-dependabot.yml at line 18, Pin every referenced
GitHub Action to an immutable commit SHA instead of a mutable tag: update
dependabot/fetch-metadata in .github/workflows/auto-merge-dependabot.yml
(18-18); checkout, pnpm setup, and setup-node in .github/workflows/ci.yml
(12-18); checkout and all CodeQL actions in .github/workflows/ci.yml (45-56);
checkout and setup-node in .github/workflows/playwright.yml (12-13); and
upload-artifact in .github/workflows/playwright.yml (22-22), preserving the
intended action versions.

Source: Linters/SAST tools

with:
github-token: "${{ secrets.GITHUB_TOKEN }}"

Expand Down
14 changes: 7 additions & 7 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,11 +9,11 @@ jobs:
validate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Sensitive Data Exposure (CWE-522): Insufficiently Protected Credentials

Reachability: External

Disable checkout credential persistence in both workflows.

  • .github/workflows/ci.yml#L12-L12: add persist-credentials: false.
  • .github/workflows/ci.yml#L45-L45: add persist-credentials: false.
  • .github/workflows/playwright.yml#L12-L12: add persist-credentials: false.
🧰 Tools
🪛 zizmor (1.26.1)

[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 12-12: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

📍 Affects 2 files
  • .github/workflows/ci.yml#L12-L12 (this comment)
  • .github/workflows/ci.yml#L45-L45
  • .github/workflows/playwright.yml#L12-L12
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml at line 12, Disable checkout credential persistence
by adding persist-credentials: false to the checkout steps at
.github/workflows/ci.yml lines 12-12 and 45-45, and
.github/workflows/playwright.yml lines 12-12.

Source: Linters/SAST tools


- uses: pnpm/action-setup@v4
- uses: pnpm/action-setup@v6

- uses: actions/setup-node@v4
- uses: actions/setup-node@v7
Comment on lines +12 to +16

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Security Misconfiguration (CWE-494): Download of Code Without Integrity Check

Reachability: External

Pin all upgraded actions to full commit SHAs.

The v7/v6/v4 tags are mutable; pin checkout, pnpm setup, setup-node, and all CodeQL actions to verified 40-character commit SHAs to prevent third-party code substitution.

Also applies to: 45-56

🧰 Tools
🪛 zizmor (1.26.1)

[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 12-12: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 14-14: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml around lines 12 - 18, Update the workflow steps
using actions/checkout, pnpm/action-setup, actions/setup-node, and every CodeQL
action to reference verified immutable 40-character commit SHAs instead of
version tags. Preserve each action’s current version and configuration while
pinning all upgraded actions consistently.

Source: Linters/SAST tools

with:
node-version: "22"
cache: pnpm
Expand Down Expand Up @@ -62,15 +62,15 @@ jobs:
contents: read
security-events: write
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7

- name: Initialize CodeQL
uses: github/codeql-action/init@v3
uses: github/codeql-action/init@v4
with:
languages: javascript-typescript

- name: Autobuild
uses: github/codeql-action/autobuild@v3
uses: github/codeql-action/autobuild@v4

- name: Perform CodeQL analysis
uses: github/codeql-action/analyze@v3
uses: github/codeql-action/analyze@v4
8 changes: 4 additions & 4 deletions .github/workflows/playwright.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,9 @@ jobs:
timeout-minutes: 60
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v4
- uses: actions/setup-node@v4
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
- uses: actions/setup-node@v7
Comment on lines +12 to +14

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Security Misconfiguration (CWE-494): Download of Code Without Integrity Check

Reachability: External

Pin all upgraded actions to full commit SHAs.

Pin checkout, setup-node, and upload-artifact to verified 40-character commit SHAs instead of mutable major-version tags.

Also applies to: 22-22

🧰 Tools
🪛 zizmor (1.26.1)

[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 12-12: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 13-13: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/playwright.yml around lines 12 - 13, Update the workflow’s
actions/checkout, actions/setup-node, and actions/upload-artifact references to
verified immutable 40-character commit SHAs, replacing their mutable
major-version tags while preserving the existing action configuration.

Source: Linters/SAST tools

with:
node-version: "22"
cache: pnpm
Expand All @@ -21,7 +21,7 @@ jobs:
run: pnpm exec playwright install --with-deps
- name: Run Playwright tests
run: pnpm exec playwright test
- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v7
if: ${{ !cancelled() }}
with:
name: playwright-report
Expand Down
Loading