From ba425e8a8750c46ec87552a3ffa5c2d7d902210b Mon Sep 17 00:00:00 2001 From: Sam Limbu Date: Thu, 27 Aug 2026 22:42:29 +1000 Subject: [PATCH] SEC-01: pin actions/checkout in the deploy workflow to a commit SHA MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit deploy.yml runs on the self-hosted VPS runner with passwordless sudo, so a mutable tag on this action is a code-execution path onto that host if the tag is ever moved. Pinned to the commit v4 currently resolves to (11d5960a326750d5838078e36cf38b85af677262), verified against upstream — this is the same code the deploy already runs today, not a version bump. ci.yml is on v7.0.1; the deploy path is deliberately left on v4 so that pinning does not smuggle a major-version change into a workflow whose only test is a live deploy. Raised by Codex review of PR #5 as the one unpinned `uses:` in either workflow. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/deploy.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index f5e7751..ae6e01f 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -20,7 +20,7 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: clean: true fetch-depth: 1