GitHub recommends actions to be pinned to their commit's SHA. For example, the recent TeamPCP compromises of the trivy & kics actions didn't impact clients who had pinned SHAs.
IIUC, SHA-pinning doesn't guarantee integrity here, because the Dockerfile pulls artifacts from a mutable cargo-deny release. A couple options come to mind:
- Making cargo-deny releases immutable, so we can trust that the artifacts of a particular release won't change under our feet
- Storing and checking artifact SHAs in the Dockerfile
WDYT?
GitHub recommends actions to be pinned to their commit's SHA. For example, the recent TeamPCP compromises of the trivy & kics actions didn't impact clients who had pinned SHAs.
IIUC, SHA-pinning doesn't guarantee integrity here, because the Dockerfile pulls artifacts from a mutable cargo-deny release. A couple options come to mind:
WDYT?