Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/static.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ jobs:
name: PHPStan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Pin actions/checkout to a specific commit SHA instead of using a version tag.

The static analysis tool (zizmor) flags both checkout steps as using unpinned action references. GitHub recommends pinning dependency versions to a specific commit SHA to prevent malicious code added to a new or updated branch or tag from being automatically used. In March 2025, the tj-actions/changed-files action used in tens of thousands of repositories was compromised; malicious code extracted CI runner secrets, and version tags were moved to point at the malicious commit; every workflow using a floating tag reference executed the malicious code automatically, while repositories pinned to specific commit hashes were unaffected.

📌 Fix: Pin to commit SHA with version comment

Replace each checkout reference with a pinned commit SHA. For example:

-      - uses: actions/checkout@v7
+      - uses: actions/checkout@de0fac2e4500dabe0009e6a0797e74b61c1c2481 # v7.0.0

To find the correct SHA for v7.0.0, visit the actions/checkout releases page and click the commit hash link.

Alternatively, use the GitHub CLI:

gh api repos/actions/checkout/commits/v7.0.0 --jq '.sha'

Also applies to: 38-38

🧰 Tools
🪛 zizmor (1.25.2)

[warning] 17-17: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 17-17: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/static.yml at line 17, The GitHub Actions workflow uses
unpinned action references with version tags (`actions/checkout@v7`), which
poses a security risk as version tags can be moved to point to malicious
commits. Replace both occurrences of `actions/checkout@v7` (at line 17 and line
38) with a pinned commit SHA reference by visiting the actions/checkout releases
page for v7.0.0, copying the specific commit hash, and using the format
`actions/checkout@<commit-sha>` with a comment indicating the version like `#
v7.0.0`. This ensures the workflow uses an immutable reference that cannot be
compromised by tag manipulation.

Source: Linters/SAST tools


- name: Setup PHP
uses: shivammathur/setup-php@v2
Expand All @@ -35,7 +35,7 @@ jobs:

steps:
- name: Checkout
uses: actions/checkout@v6
uses: actions/checkout@v7

- name: Setup PHP
uses: shivammathur/setup-php@v2
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@v6
uses: actions/checkout@v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Pin actions/checkout to a specific commit SHA instead of using a version tag.

The static analysis tool (zizmor) flags this checkout step as using an unpinned action reference. Pinning an action to a full-length commit SHA is the most reliable way to use an immutable version of an action, and pinning to a specific SHA mitigates the risk of a bad actor changing a tag to point to malicious code.

📌 Fix: Pin to commit SHA with version comment

Replace the checkout reference with a pinned commit SHA:

       - name: Checkout code
-        uses: actions/checkout@v7
+        uses: actions/checkout@de0fac2e4500dabe0009e6a0797e74b61c1c2481 # v7.0.0

To find the correct SHA for v7.0.0, visit the actions/checkout releases page and click the commit hash link.

📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
uses: actions/checkout@v7
uses: actions/checkout@de0fac2e4500dabe0009e6a0797e74b61c1c2481 # v7.0.0
🧰 Tools
🪛 zizmor (1.25.2)

[warning] 29-30: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 30-30: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/tests.yml at line 30, The actions/checkout@v7 reference in
the workflow is using a version tag instead of being pinned to a specific commit
SHA, which poses a security risk. Replace the version tag reference with a
full-length commit SHA by visiting the actions/checkout releases page for
v7.0.0, finding the commit hash link, and updating the uses statement to pin to
that specific commit SHA rather than the mutable version tag. This ensures the
workflow uses an immutable reference to the action.

Source: Linters/SAST tools


- name: Setup PHP
uses: shivammathur/setup-php@v2
Expand Down