ci: pin actions to SHAs and gate workflows on actionlint + zizmor
CI / build (push) Successful in 49s
CI / workflows (push) Successful in 16s
Release / release (push) Failing after 19s

Pins every action to the latest release SHA within its current major, so
no untested major bump rides along: checkout v4.4.0, setup-go v5.6.0,
upload-artifact v4.6.2, download-artifact v4.3.0, action-gh-release v2.6.2.

Adds a `workflows` CI job running actionlint and zizmor. actionlint comes
from `go install` (module proxy checksums cover integrity); zizmor has no
published checksums, so its release tarball is pinned by version and
verified against a recorded sha256. The gate uses --min-severity=low, which
fails on low and above while tolerating the one informational
superfluous-actions advisory.

zizmor only collects from .github/workflows: pointing it at .gitea/workflows
yields "no inputs collected", and when both directories are passed it audits
only .github and still exits 0. The gate therefore passes explicit *.yml
paths, which is the only form that actually audits the Gitea workflows.

Auditing them for the first time surfaced seven findings, now fixed:
credential persistence on checkout (persist-credentials: false), setup-go
caching on the release path (cache: false), and missing top-level
permissions (contents: read, with contents: write narrowed to the GitHub
release job that needs it).
This commit is contained in:
2026-07-21 15:16:55 -05:00
parent 5b101bc6dd
commit 250b3e98ca
3 changed files with 73 additions and 12 deletions
+54 -4
View File
@@ -1,5 +1,8 @@
name: CI name: CI
permissions:
contents: read
on: on:
push: push:
branches: [main] branches: [main]
@@ -8,7 +11,8 @@ on:
- 'go.mod' - 'go.mod'
- 'go.sum' - 'go.sum'
- 'Makefile' - 'Makefile'
- '.gitea/workflows/ci.yml' - '.gitea/workflows/**'
- '.github/workflows/**'
pull_request: pull_request:
branches: [main] branches: [main]
paths: paths:
@@ -16,7 +20,8 @@ on:
- 'go.mod' - 'go.mod'
- 'go.sum' - 'go.sum'
- 'Makefile' - 'Makefile'
- '.gitea/workflows/ci.yml' - '.gitea/workflows/**'
- '.github/workflows/**'
jobs: jobs:
build: build:
@@ -24,12 +29,15 @@ jobs:
timeout-minutes: 15 timeout-minutes: 15
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
persist-credentials: false
- name: Set up Go - name: Set up Go
uses: actions/setup-go@v5 uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with: with:
go-version: '1.25' go-version: '1.25'
cache: false
- name: Format check - name: Format check
run: | run: |
@@ -48,3 +56,45 @@ jobs:
- name: Static build - name: Static build
run: CGO_ENABLED=0 go build -ldflags="-w -s" -o shush ./cmd/shush run: CGO_ENABLED=0 go build -ldflags="-w -s" -o shush ./cmd/shush
workflows:
runs-on: cpu
timeout-minutes: 10
steps:
- name: Checkout
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
persist-credentials: false
- name: Set up Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: '1.25'
cache: false
- name: Install actionlint
run: go install github.com/rhysd/actionlint/cmd/[email protected]
- name: Install zizmor
env:
ZIZMOR_VERSION: '1.27.0'
ZIZMOR_SHA256: '277f2bd8fd37cf60c42ab7afca6faa884e65440fa31e02b44bdaae60f62a358f'
run: |
set -euo pipefail
url="https://github.com/zizmorcore/zizmor/releases/download/v${ZIZMOR_VERSION}/zizmor-x86_64-unknown-linux-gnu.tar.gz"
curl -sSLf -o zizmor.tar.gz "$url"
echo "${ZIZMOR_SHA256} zizmor.tar.gz" | sha256sum -c -
tar xzf zizmor.tar.gz
install -m 0755 zizmor "$(go env GOPATH)/bin/zizmor"
- name: actionlint
run: |
gopath="$(go env GOPATH)"
export PATH="$gopath/bin:$PATH"
actionlint .gitea/workflows/*.yml .github/workflows/*.yml
- name: zizmor
run: |
gopath="$(go env GOPATH)"
export PATH="$gopath/bin:$PATH"
zizmor --min-severity=low .gitea/workflows/*.yml .github/workflows/*.yml
+8 -2
View File
@@ -1,5 +1,8 @@
name: Release name: Release
permissions:
contents: read
on: on:
push: push:
tags: ['v*'] tags: ['v*']
@@ -11,12 +14,15 @@ jobs:
timeout-minutes: 20 timeout-minutes: 20
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
persist-credentials: false
- name: Set up Go - name: Set up Go
uses: actions/setup-go@v5 uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with: with:
go-version: '1.25' go-version: '1.25'
cache: false
- name: Build cross-platform binaries - name: Build cross-platform binaries
run: | run: |
+11 -6
View File
@@ -1,6 +1,6 @@
name: Build and Release name: Build and Release
permissions: permissions:
contents: write contents: read
on: on:
push: push:
@@ -34,12 +34,15 @@ jobs:
steps: steps:
- name: Checkout code - name: Checkout code
uses: actions/checkout@v4 uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
persist-credentials: false
- name: Set up Go - name: Set up Go
uses: actions/setup-go@v5 uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with: with:
go-version: '1.25' go-version: '1.25'
cache: false
- name: Install cross-compilation tools - name: Install cross-compilation tools
run: | run: |
@@ -72,7 +75,7 @@ jobs:
# The artifact upload will pick up both files # The artifact upload will pick up both files
- name: Upload artifacts - name: Upload artifacts
uses: actions/upload-artifact@v4 uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with: with:
name: shush-${{ matrix.platform.os }}-${{ matrix.platform.arch }} name: shush-${{ matrix.platform.os }}-${{ matrix.platform.arch }}
path: shush* path: shush*
@@ -82,9 +85,11 @@ jobs:
name: Create Release name: Create Release
needs: build needs: build
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions:
contents: write
steps: steps:
- name: Download all artifacts - name: Download all artifacts
uses: actions/download-artifact@v4 uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with: with:
path: artifacts path: artifacts
@@ -95,7 +100,7 @@ jobs:
ls -la release-assets/ ls -la release-assets/
- name: Create release - name: Create release
uses: softprops/action-gh-release@v2 uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2.6.2
with: with:
files: release-assets/* files: release-assets/*
fail_on_unmatched_files: true fail_on_unmatched_files: true