Summary
Several CI/CD hygiene gaps: unpinned actions in the docs workflow, an archived action in the release pipeline, a files: '**' release upload, cosign installed but never used, floating base images, and a stale cargo-deny advisory ignore.
Evidence
.github/workflows/docs.yml:34,60,73 — actions/setup-python@v6 and peaceiris/actions-gh-pages@v4 are floating major tags (the only unpinned actions in the repo; everything else is SHA-pinned).
.github/workflows/release.yml:77 — actions/create-release@0cb9c9b… is the archived (2021) actions/create-release action, redundant with the softprops/action-gh-release already used at release.yml:93.
.github/workflows/release.yml:96 — files: '**' uploads the entire checked-out repo plus artifacts to the release (softprops skips only dotfiles); should be vym-fyi-client-*.
.github/workflows/build.yml:126-127 — sigstore/cosign-installer runs but no cosign sign step exists; images are never signed despite id-token: write being granted.
Dockerfile:3,73 — FROM rust:1 and FROM gcr.io/distroless/static-debian12:nonroot are floating tags (crate deps are correctly locked via Cargo.lock + --locked).
deny.toml:17-19 — the ignore for RUSTSEC-2023-0071 (time 0.1.x) is stale: time is not in the dependency tree, so the ignore would silently permit a reintroduced vulnerable time.
Severity: LOW.
Suggested fix
- Pin
setup-python and actions-gh-pages to SHAs.
- Remove the archived
actions/create-release step.
- Narrow
files: '**' to the actual artifacts.
- Add a
cosign sign step (keyless, using the existing OIDC token) and document verification.
- Pin base images to versioned tags or digests.
- Remove the stale
time advisory ignore (and ideally make advisories blocking — see the scan-after-publish issue).
Summary
Several CI/CD hygiene gaps: unpinned actions in the docs workflow, an archived action in the release pipeline, a
files: '**'release upload, cosign installed but never used, floating base images, and a stalecargo-denyadvisory ignore.Evidence
.github/workflows/docs.yml:34,60,73—actions/setup-python@v6andpeaceiris/actions-gh-pages@v4are floating major tags (the only unpinned actions in the repo; everything else is SHA-pinned)..github/workflows/release.yml:77—actions/create-release@0cb9c9b…is the archived (2021)actions/create-releaseaction, redundant with thesoftprops/action-gh-releasealready used atrelease.yml:93..github/workflows/release.yml:96—files: '**'uploads the entire checked-out repo plus artifacts to the release (softprops skips only dotfiles); should bevym-fyi-client-*..github/workflows/build.yml:126-127—sigstore/cosign-installerruns but nocosign signstep exists; images are never signed despiteid-token: writebeing granted.Dockerfile:3,73—FROM rust:1andFROM gcr.io/distroless/static-debian12:nonrootare floating tags (crate deps are correctly locked viaCargo.lock+--locked).deny.toml:17-19— the ignore for RUSTSEC-2023-0071 (time0.1.x) is stale:timeis not in the dependency tree, so the ignore would silently permit a reintroduced vulnerabletime.Severity: LOW.
Suggested fix
setup-pythonandactions-gh-pagesto SHAs.actions/create-releasestep.files: '**'to the actual artifacts.cosign signstep (keyless, using the existing OIDC token) and document verification.timeadvisory ignore (and ideally make advisories blocking — see the scan-after-publish issue).