Skip to content

CI hygiene: unpinned actions, archived action, files '**', cosign unused, floating base images, stale deny ignore #139

Description

@stephane-segning

Summary

Several CI/CD hygiene gaps: unpinned actions in the docs workflow, an archived action in the release pipeline, a files: '**' release upload, cosign installed but never used, floating base images, and a stale cargo-deny advisory ignore.

Evidence

  • .github/workflows/docs.yml:34,60,73 — actions/setup-python@v6 and peaceiris/actions-gh-pages@v4 are floating major tags (the only unpinned actions in the repo; everything else is SHA-pinned).
  • .github/workflows/release.yml:77 — actions/create-release@0cb9c9b… is the archived (2021) actions/create-release action, redundant with the softprops/action-gh-release already used at release.yml:93.
  • .github/workflows/release.yml:96 — files: '**' uploads the entire checked-out repo plus artifacts to the release (softprops skips only dotfiles); should be vym-fyi-client-*.
  • .github/workflows/build.yml:126-127 — sigstore/cosign-installer runs but no cosign sign step exists; images are never signed despite id-token: write being granted.
  • Dockerfile:3,73 — FROM rust:1 and FROM gcr.io/distroless/static-debian12:nonroot are floating tags (crate deps are correctly locked via Cargo.lock + --locked).
  • deny.toml:17-19 — the ignore for RUSTSEC-2023-0071 (time 0.1.x) is stale: time is not in the dependency tree, so the ignore would silently permit a reintroduced vulnerable time.

Severity: LOW.

Suggested fix

  • Pin setup-python and actions-gh-pages to SHAs.
  • Remove the archived actions/create-release step.
  • Narrow files: '**' to the actual artifacts.
  • Add a cosign sign step (keyless, using the existing OIDC token) and document verification.
  • Pin base images to versioned tags or digests.
  • Remove the stale time advisory ignore (and ideally make advisories blocking — see the scan-after-publish issue).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity findings and hardening

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions