Skip to content

harden(janitor): SHA-pin actions/checkout (org-token-handling action) - #22

Open
asachs01 wants to merge 2 commits into
mainfrom
fix/janitor-gap2-pin-checkout
Open

harden(janitor): SHA-pin actions/checkout (org-token-handling action)#22
asachs01 wants to merge 2 commits into
mainfrom
fix/janitor-gap2-pin-checkout

Conversation

@asachs01

Copy link
Copy Markdown
Member

GAP-2 (warden-elevated): the janitor's checkout step persists the org-wide app-token into .git/config (backlog push). Floating @v4 → repointed-tag = org-token exfil = fleet compromise. SHA-pin to v4.3.0 per CI-QW-3. Pure pin, zero behavior change. Ready for Aaron approve + warden security-glance.

…pp-token)

GAP-2 (warden severity-elevated): the checkout step does token: ${{ steps.app-token.outputs.token }}
to push the backlog, persisting the ORG-WIDE Contents+PR app-token into .git/config. A
floating @v4 tag → a repointed/compromised tag could exfiltrate the crown-jewel token =
fleet-wide compromise. SHA-pin to v4.3.0 (34e114876b0b11c390a56381ad16ebd13914f8d5) per
CI-QW-3. Pure pin, zero behavior change. (create-github-app-token was already pinned.)
warden pin-legitimacy check: 34e114876b0b11c390a56381ad16ebd13914f8d5 is checkout
v4.3.1 (current v4 head), NOT v4.3.0 (=08eba0b). SHA is legitimate; the comment
mislabeled the version. SHA + comment must AGREE (the comment is how a human audits
the intended version). Corrected to v4.3.1 (latest v4 patch, fine to pin).
@asachs01

Copy link
Copy Markdown
Member Author

warden pin-legitimacy catch: 34e1148 = v4.3.1 (current v4 head), not v4.3.0 (=08eba0b). SHA is legit; comment was mislabeled → corrected to # v4.3.1. SHA+comment now agree.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

1 participant