Repository navigation
ci: bump the actions group across 1 directory with 6 updates #2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -9,11 +9,11 @@ jobs: | |
| validate: | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win Sensitive Data Exposure (CWE-522): Insufficiently Protected Credentials Reachability: External Disable checkout credential persistence in both workflows.
🧰 Tools🪛 zizmor (1.26.1)[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) [error] 12-12: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 📍 Affects 2 files
🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
|
|
||
| - uses: pnpm/action-setup@v4 | ||
| - uses: pnpm/action-setup@v6 | ||
|
|
||
| - uses: actions/setup-node@v4 | ||
| - uses: actions/setup-node@v7 | ||
|
Comment on lines
+12
to
+16
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win Security Misconfiguration (CWE-494): Download of Code Without Integrity Check Reachability: External Pin all upgraded actions to full commit SHAs. The Also applies to: 45-56 🧰 Tools🪛 zizmor (1.26.1)[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) [error] 12-12: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) [error] 14-14: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) [error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
| with: | ||
| node-version: "22" | ||
| cache: pnpm | ||
|
|
@@ -62,15 +62,15 @@ jobs: | |
| contents: read | ||
| security-events: write | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 | ||
|
|
||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@v3 | ||
| uses: github/codeql-action/init@v4 | ||
| with: | ||
| languages: javascript-typescript | ||
|
|
||
| - name: Autobuild | ||
| uses: github/codeql-action/autobuild@v3 | ||
| uses: github/codeql-action/autobuild@v4 | ||
|
|
||
| - name: Perform CodeQL analysis | ||
| uses: github/codeql-action/analyze@v3 | ||
| uses: github/codeql-action/analyze@v4 | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -9,9 +9,9 @@ jobs: | |
| timeout-minutes: 60 | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: pnpm/action-setup@v4 | ||
| - uses: actions/setup-node@v4 | ||
| - uses: actions/checkout@v7 | ||
| - uses: pnpm/action-setup@v6 | ||
| - uses: actions/setup-node@v7 | ||
|
Comment on lines
+12
to
+14
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win Security Misconfiguration (CWE-494): Download of Code Without Integrity Check Reachability: External Pin all upgraded actions to full commit SHAs. Pin checkout, setup-node, and upload-artifact to verified 40-character commit SHAs instead of mutable major-version tags. Also applies to: 22-22 🧰 Tools🪛 zizmor (1.26.1)[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) [error] 12-12: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) [error] 13-13: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
| with: | ||
| node-version: "22" | ||
| cache: pnpm | ||
|
|
@@ -21,7 +21,7 @@ jobs: | |
| run: pnpm exec playwright install --with-deps | ||
| - name: Run Playwright tests | ||
| run: pnpm exec playwright test | ||
| - uses: actions/upload-artifact@v4 | ||
| - uses: actions/upload-artifact@v7 | ||
| if: ${{ !cancelled() }} | ||
| with: | ||
| name: playwright-report | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🔴 Critical | ⚡ Quick win
Security Misconfiguration (CWE-494): Download of Code Without Integrity Check
Reachability: External
Pin every upgraded action to an immutable commit SHA. Mutable tags allow action code to change without a workflow diff; this is especially dangerous in
.github/workflows/auto-merge-dependabot.yml, which runs under write permissions..github/workflows/auto-merge-dependabot.yml#L18-L18: pindependabot/fetch-metadata..github/workflows/ci.yml#L12-L18: pin checkout, pnpm setup, and setup-node..github/workflows/ci.yml#L45-L56: pin checkout and all CodeQL actions..github/workflows/playwright.yml#L12-L13: pin checkout and setup-node..github/workflows/playwright.yml#L22-L22: pin upload-artifact.🧰 Tools
🪛 zizmor (1.26.1)
[error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
📍 Affects 3 files
.github/workflows/auto-merge-dependabot.yml#L18-L18(this comment).github/workflows/ci.yml#L12-L18.github/workflows/ci.yml#L45-L56.github/workflows/playwright.yml#L12-L13.github/workflows/playwright.yml#L22-L22🤖 Prompt for AI Agents
Source: Linters/SAST tools