Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,7 @@ jobs:
with:
persist-credentials: false

- uses: actions/setup-python@v5
- uses: actions/setup-python@v7
with:
python-version: "3.12"
cache: pip
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/dependabot-auto-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:
steps:
- name: Check if PR can be merged
id: check
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
result-encoding: string
script: |
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/kb-update.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ jobs:
with:
persist-credentials: false

- uses: actions/setup-python@v5
- uses: actions/setup-python@v7
with:
python-version: "3.12"
cache: pip
Expand All @@ -42,7 +42,7 @@ jobs:

- name: Upload report
if: ${{ !cancelled() }}
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: kb-update-report
path: |
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/tauri-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,15 +16,15 @@ jobs:
build-windows:
runs-on: windows-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Pin every upgraded GitHub Action to an immutable commit SHA.

All changed action references use mutable major-version tags. This violates the repository’s blanket zizmor policy and leaves CI behavior dependent on tag movement.

  • .github/workflows/tauri-build.yml#L19-L19: pin actions/checkout@v7.
  • .github/workflows/tauri-build.yml#L22-L22: pin actions/setup-node@v7.
  • .github/workflows/tauri-build.yml#L27-L27: pin pnpm/action-setup@v6.
  • .github/workflows/tauri-build.yml#L54-L54: pin the NSIS actions/upload-artifact@v7.
  • .github/workflows/tauri-build.yml#L61-L61: pin the MSI actions/upload-artifact@v7.
  • .github/workflows/ci.yml#L110-L110: pin actions/setup-python@v7.
  • .github/workflows/dependabot-auto-merge.yml#L25-L25: pin actions/github-script@v9.
  • .github/workflows/kb-update.yml#L24-L24: pin actions/setup-python@v7.
  • .github/workflows/kb-update.yml#L45-L45: pin actions/upload-artifact@v7.
🧰 Tools
🪛 zizmor (1.28.0)

[warning] 19-19: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 19-19: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

📍 Affects 4 files
  • .github/workflows/tauri-build.yml#L19-L19 (this comment)
  • .github/workflows/tauri-build.yml#L22-L22
  • .github/workflows/tauri-build.yml#L27-L27
  • .github/workflows/tauri-build.yml#L54-L54
  • .github/workflows/tauri-build.yml#L61-L61
  • .github/workflows/ci.yml#L110-L110
  • .github/workflows/dependabot-auto-merge.yml#L25-L25
  • .github/workflows/kb-update.yml#L24-L24
  • .github/workflows/kb-update.yml#L45-L45
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/tauri-build.yml at line 19, Replace every mutable action
tag with the corresponding immutable commit SHA: pin actions/checkout@v7,
actions/setup-node@v7, pnpm/action-setup@v6, both NSIS and MSI
actions/upload-artifact@v7 references in .github/workflows/tauri-build.yml
(lines 19, 22, 27, 54, and 61), actions/setup-python@v7 in
.github/workflows/ci.yml (line 110), actions/github-script@v9 in
.github/workflows/dependabot-auto-merge.yml (line 25), and
actions/setup-python@v7 plus actions/upload-artifact@v7 in
.github/workflows/kb-update.yml (lines 24 and 45). Preserve each action version
while replacing only the mutable tag with its full commit SHA.

Source: Linters/SAST tools


- name: Setup Node.js
uses: actions/setup-node@v4
uses: actions/setup-node@v7
with:
node-version: 22

- name: Setup pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@v6
with:
version: 11.17

Expand All @@ -51,14 +51,14 @@ jobs:
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}

- name: Upload NSIS artifact
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: olive-studio-nsis
path: src-tauri/target/x86_64-pc-windows-msvc/release/bundle/nsis/*.exe
if-no-files-found: error

- name: Upload MSI artifact
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: olive-studio-msi
path: src-tauri/target/x86_64-pc-windows-msvc/release/bundle/msi/*.msi
Expand Down
Loading