Skip to content

chore: use grok-build-0.1 for SquidGate - #1

Merged
DotNetRussell merged 2 commits into
mainfrom
chore/squidgate-grok-build-0.1
Aug 1, 2026
Merged

chore: use grok-build-0.1 for SquidGate#1
DotNetRussell merged 2 commits into
mainfrom
chore/squidgate-grok-build-0.1

Conversation

@DotNetRussell

Copy link
Copy Markdown
Collaborator

Point SquidGate at xAI grok-build-0.1 (custom provider, api.x.ai). Uses LLM_API_KEY repo secret.

@github-actions

github-actions Bot commented Aug 1, 2026

Copy link
Copy Markdown

🛡️ Security Scan Results

The added workflow uses an unpinned third-party action, introducing a supply chain risk.

MEDIUM — Unpinned third-party GitHub Action

File: .github/workflows/squidgate.yml:21 | Confidence: high | Category: supply_chain

The workflow references the third-party action 'SquidSec/SquidGate@v1' using a mutable tag instead of a specific commit SHA. This allows supply chain attacks if the tag is moved to point to malicious code.

CWE: CWE-829 | OWASP: A06:2021

Recommendation: Pin to a full commit SHA: uses: SquidSec/SquidGate@. Consider the same for actions/checkout@v4.


@DotNetRussell
DotNetRussell merged commit 41888da into main Aug 1, 2026
2 checks passed
@DotNetRussell
DotNetRussell deleted the chore/squidgate-grok-build-0.1 branch August 1, 2026 12:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant