How to avoid outdated images with unpinned-images
#2089
Replies: 2 comments
|
Ah yeah, I think Dependabot unfortunately can't do that. I believe Renovate can, but I'm less familiar with it. I believe @tnytown was looking a bit into a "stale OCI images" audit, but it's nontrivial (since we'd need to contact arbitrary OCI registries + deal with their auth). But long term that's something I'm interested in zizmor being able to flag as well 🙂 |
|
Expanding on @woodruffw's answer — here are the concrete options for keeping pinned images up to date without manual work: Option 1: Renovate (recommended)Renovate supports updating container image references in GitHub Actions workflow files. It can bump Configure {
"extends": ["config:recommended"],
"packageRules": [
{
"matchManagers": ["github-actions"],
"matchDatasources": ["docker"],
"pinDigests": true
}
]
}This pins to Option 2: Pin to a floating tag with digest fallbackIf you need to track a rolling tag (e.g., - name: Resolve image digest
id: digest
run: |
digest=$(docker buildx imagetools inspect myimage:latest --format '{{json .Manifest.Digest}}' | tr -d '"')
echo "digest=$digest" >> "$GITHUB_OUTPUT"Then use the resolved digest in subsequent steps. This is more of a CI pattern than a zizmor workaround, but it satisfies the audit while keeping the image current. Option 3: Accept the risk and suppressIf you intentionally want a floating tag (e.g., for a dev workflow), suppress the finding with a zizmor --ignore unpinned-images .Or in the audit config: unpinned-images:
ignore:
- .github/workflows/dev.ymlWhy Dependabot can't do thisDependabot's GitHub Actions manager handles Summary
For production workflows, Renovate is the cleanest answer. For dev/throwaway workflows, suppressing is fine. |
Uh oh!
There was an error while loading. Please reload this page.
I have some images that use a release branch, but they are flagged by the unpinned-images check. Fair enough, but if I pin them they will quickly become outdated. Can Dependabot be configured to update these references in GitHub actions somehow, or is this just something you'll need to manually fix?
Ref: https://docs.zizmor.sh/audits/#unpinned-images
All reactions