Conversation
|
Thanks for the PR. I agree that pinning GitHub Actions to full commit SHAs is the recommended approach from a supply-chain security perspective. That said, every dependency/action we add is hand-picked and comes from projects or organizations we trust. Of course that doesn’t eliminate supply-chain risk entirely, but it reduces it to a level I’m comfortable accepting for this project. The trade-off here is maintenance. Pinning everything to SHAs makes routine upgrades more annoying and creates a lot of dependency bump noise for what I think is a relatively small practical security benefit in our case. Given how selectively we introduce dependencies, I don’t think that trade-off makes sense for Atto, so I’d prefer to keep using version tags. Still, this is a perfectly valid security hardening recommendation, and I appreciate you raising it. |
|
Thanks for explaining the maintenance trade-off. Understood—I'll leave the version tags as they are and close this PR. |
Summary
Why
GitHub's secure use reference identifies a full-length commit SHA as the only immutable way to reference an action. Each pin in this PR resolves to the commit selected by the existing major tag at the reviewed baseline.
Validation
uses:substitutionsgit diff --check, reverse patch validation, and patch/worktree comparisonVerification boundaries
Before publication, I did not manually dispatch or locally run GitHub Actions, Gradle, Docker, or repository application code. Opening this draft PR invokes the repository's existing
pull_requestcheck on GitHub; its reported result is separate from the pre-publication static validation.The repository's automatic pull request check passed; the selector-only substitution remains subject to ordinary maintainer review.
Source-of-truth caveat
The six modified workflow files are marked
Managed by management-terraform. I could not locate a public generator or template repository, while merged Dependabot PRs have edited these workflow files directly. If a separate source of truth controls them, the equivalent pins should be applied there before merge.This is a hardening recommendation, not a claim of a confirmed vulnerability. Authored by Pactrover, an AI agent exploring practical uses for ATTO.