Skip to content

Commit dcd4441

Browse files
Pin GitHub Actions to full-length commit SHAs (#457)
## Summary This PR pins GitHub Actions to full-length commit SHAs for improved security and reproducibility and adds a 7 day cooldown to Dependabot configuration for GitHub Actions. This work is described in more detail at https://aka.ms/action-pinning. ## Why? Pinning actions to commit SHAs prevents supply-chain attacks where a tag could be moved to point to malicious code. This is a recommended security best practice per the [GitHub Actions security hardening guide](https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions#using-third-party-actions). This change mitigates the risk of tag retargeting to malicious code as seen in incidents like the [tj-actions/changed-files action compromise](https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised) or [codfish/semantic-release-action compromise](https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action) and improves the integrity and reproducibility of the CI/CD pipeline. ## What changed? **Action pinning:** Third-party action references in `.github/workflows/` that used mutable tag-based references (e.g., `actions/checkout@v4`) have been updated to full-length commit SHAs with a version comment (e.g., `actions/checkout@<sha> # v4`) using the [pinact](https://github.com/suzuki-shunsuke/pinact) tool. References that were already pinned to a SHA, or that used immutable release tags, were left unchanged. **Dependabot configuration:** `.github/dependabot.yml` has been updated to ensure a `github-actions` package-ecosystem section is present with a `cooldown` configuration (`default-days: 7`). This groups Dependabot PRs for GitHub Actions and enforces a minimum 7-day cooldown between updates. If the file did not exist, it was created. If a `github-actions` section already existed, only the `cooldown` block was added or its `default-days` value was increased to 7 if it was lower. The 7-day cooldown provides a window for the community to detect and report compromised releases before they are automatically proposed as updates, reducing exposure to supply-chain attacks via newly published malicious versions. ## Is this safe to merge? Yes. The pinned SHAs correspond to the same commits that the existing tags pointed to. No behavioral changes are introduced. You can verify the pinned SHA value using the GitHub REST API (e.g., the commit hash for `actions/checkout@v7` can be found in the `sha` property in the JSON response for `GET https://api.github.com/repos/actions/checkout/commits/v7`). ## Additional Information For more information, please see https://aka.ms/action-pinning
1 parent 734c1f3 commit dcd4441

9 files changed

Lines changed: 20 additions & 20 deletions

‎.github/workflows/issue-assignment.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,5 +19,5 @@ on:
1919
jobs:
2020
apply:
2121

22-
uses: microsoft/mu_devops/.github/workflows/IssueAssignment.yml@v18.0.7
22+
uses: microsoft/mu_devops/.github/workflows/IssueAssignment.yml@131433bb4f29d68250154cc66096f04c19fe3ee9 # v18.0.7
2323
secrets: inherit

‎.github/workflows/label-sync.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,5 +25,5 @@ on:
2525
jobs:
2626
sync:
2727

28-
uses: microsoft/mu_devops/.github/workflows/LabelSyncer.yml@v18.0.7
28+
uses: microsoft/mu_devops/.github/workflows/LabelSyncer.yml@131433bb4f29d68250154cc66096f04c19fe3ee9 # v18.0.7
2929
secrets: inherit

‎.github/workflows/prepare-binaries.yml‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -32,19 +32,19 @@ jobs:
3232

3333
steps:
3434
- name: Checkout Self
35-
uses: actions/checkout@v7
35+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
3636

3737
- name: Generate Token
3838
if: github.event_name == 'release'
3939
id: app-token
40-
uses: actions/create-github-app-token@v3
40+
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
4141
with:
4242
app-id: ${{ vars.MU_ACCESS_APP_ID }}
4343
private-key: ${{ secrets.MU_ACCESS_APP_PRIVATE_KEY }}
4444
owner: ${{ github.repository_owner }}
4545

4646
- name: Set up Python
47-
uses: actions/setup-python@v6
47+
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
4848
with:
4949
python-version: 3.12
5050
cache: 'pip'
@@ -80,7 +80,7 @@ jobs:
8080
run: python scripts/secure_boot_default_keys.py --keystore Templates/LegacyFirmwareDefaults.toml -o FirmwareArtifacts
8181

8282
- name: Upload Firmware Binaries as Artifacts
83-
uses: actions/upload-artifact@v7
83+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
8484
with:
8585
name: Binaries
8686
path: FirmwareArtifacts/
@@ -90,7 +90,7 @@ jobs:
9090
if: startsWith(github.ref, 'refs/tags/')
9191

9292
- name: Upload Firmware Release Archive
93-
uses: softprops/action-gh-release@v3
93+
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2
9494
if: startsWith(github.ref, 'refs/tags/') && !endsWith(github.event.release.tag_name, '-signed')
9595
with:
9696
files: ReleaseFirmwareArchive/*
@@ -101,7 +101,7 @@ jobs:
101101
if: startsWith(github.ref, 'refs/tags/')
102102

103103
- name: Upload Signed Release Archive
104-
uses: softprops/action-gh-release@v3
104+
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2
105105
if: startsWith(github.ref, 'refs/tags/') && endsWith(github.event.release.tag_name, '-signed')
106106
with:
107107
files: ReleaseSignedArtifacts/*

‎.github/workflows/pull-request-formatting-validator.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727
steps:
2828
- name: Generate Token
2929
id: app-token
30-
uses: actions/create-github-app-token@v3
30+
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
3131
with:
3232
app-id: ${{ vars.MU_ACCESS_APP_ID }}
3333
private-key: ${{ secrets.MU_ACCESS_APP_PRIVATE_KEY }}
@@ -68,7 +68,7 @@ jobs:
6868
6969
- name: Check for Validation Errors
7070
if: env.VALIDATION_ERROR
71-
uses: actions/github-script@v9
71+
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
7272
with:
7373
script: |
7474
core.setFailed('PR Formatting Validation Check Failed!')

‎.github/workflows/release-draft.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,5 +29,5 @@ jobs:
2929
draft:
3030
name: Draft Releases
3131

32-
uses: microsoft/mu_devops/.github/workflows/ReleaseDrafter.yml@v18.0.7
32+
uses: microsoft/mu_devops/.github/workflows/ReleaseDrafter.yml@131433bb4f29d68250154cc66096f04c19fe3ee9 # v18.0.7
3333
secrets: inherit

‎.github/workflows/scheduled-maintenance.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ jobs:
2828
steps:
2929
- name: Generate Token
3030
id: app-token
31-
uses: actions/create-github-app-token@v3
31+
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
3232
with:
3333
app-id: ${{ vars.MU_ACCESS_APP_ID }}
3434
private-key: ${{ secrets.MU_ACCESS_APP_PRIVATE_KEY }}

‎.github/workflows/stale.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,5 +25,5 @@ on:
2525
jobs:
2626
check:
2727

28-
uses: microsoft/mu_devops/.github/workflows/Stale.yml@v18.0.7
28+
uses: microsoft/mu_devops/.github/workflows/Stale.yml@131433bb4f29d68250154cc66096f04c19fe3ee9 # v18.0.7
2929
secrets: inherit

‎.github/workflows/triage-issues.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,5 +20,5 @@ on:
2020
jobs:
2121
triage:
2222

23-
uses: microsoft/mu_devops/.github/workflows/IssueTriager.yml@v18.0.7
23+
uses: microsoft/mu_devops/.github/workflows/IssueTriager.yml@131433bb4f29d68250154cc66096f04c19fe3ee9 # v18.0.7
2424
secrets: inherit

‎.github/workflows/validate-kek-updates.yml‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -24,12 +24,12 @@ jobs:
2424

2525
steps:
2626
- name: Checkout PR
27-
uses: actions/checkout@v7
27+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2828
with:
2929
fetch-depth: 0 # Need full history to compare with base branch
3030

3131
- name: Set up Python
32-
uses: actions/setup-python@v6
32+
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
3333
with:
3434
python-version: 3.12
3535
cache: 'pip'
@@ -191,7 +191,7 @@ jobs:
191191
192192
- name: Upload Validation Results
193193
if: steps.changed-files.outputs.has_changes == 'true' && always()
194-
uses: actions/upload-artifact@v7
194+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
195195
with:
196196
name: kek-validation-results
197197
path: kek_validation_results/
@@ -201,7 +201,7 @@ jobs:
201201
id: app-token
202202
if: steps.changed-files.outputs.has_changes == 'true' && always()
203203
continue-on-error: true
204-
uses: actions/create-github-app-token@v3
204+
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
205205
with:
206206
app-id: ${{ vars.MU_ACCESS_APP_ID }}
207207
private-key: ${{ secrets.MU_ACCESS_APP_PRIVATE_KEY }}
@@ -210,7 +210,7 @@ jobs:
210210
- name: Comment on PR
211211
if: steps.changed-files.outputs.has_changes == 'true' && failure() && steps.app-token.outputs.token
212212
continue-on-error: true
213-
uses: actions/github-script@v9
213+
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
214214
with:
215215
github-token: ${{ steps.app-token.outputs.token }}
216216
script: |
@@ -247,7 +247,7 @@ jobs:
247247
- name: Update PR Comment on Success
248248
if: steps.changed-files.outputs.has_changes == 'true' && success() && steps.app-token.outputs.token
249249
continue-on-error: true
250-
uses: actions/github-script@v9
250+
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
251251
with:
252252
github-token: ${{ steps.app-token.outputs.token }}
253253
script: |

0 commit comments

Comments
 (0)