Skip to content

ci: pin action SHAs and add auto-tag release workflow - #36

Merged
RealDougEubanks merged 3 commits into
mainfrom
feature/pin-action-shas-and-auto-release
Sep 10, 2026
Merged

RealDougEubanks merged 3 commits into
mainfrom
feature/pin-action-shas-and-auto-release

Conversation

@RealDougEubanks

Copy link
Copy Markdown
Owner

Summary

  • Pin all action SHAs: every uses: line in lint.yml and release.yml is now pinned to a commit SHA instead of a mutable tag (e.g. @v4 → @sha256), closing the supply chain attack surface where a tag could be repointed to malicious code.
  • Upgrade while pinning: bumped hadolint/hadolint-action to v3.5.0 (supersedes Dependabot PR ci: bump hadolint/hadolint-action from 3.3.0 to 3.5.0 #33), docker/login-action to v4.6.0 (supersedes PR ci: bump docker/login-action from 4 to 4.5.2 #31), and softprops/action-gh-release to v3.0.3 (supersedes PR ci: bump softprops/action-gh-release from 3.0.0 to 3.0.3 #34).
  • Auto-tag workflow (auto-tag.yml): on every push to main, reads the semver from synology/INFO, and if no matching vMAJOR.MINOR.PATCH tag exists, creates and pushes it. This triggers the existing release.yml automatically — the release flow is now: bump version in synology/INFO + CHANGELOG.md → merge PR → tag created → Docker multi-arch image pushed → GitHub Release published.

Copilot Autofix note

Copilot Autofix for CodeQL alerts is automatically enabled on public repos — no workflow change needed. When CodeQL opens an alert, a "Fix with Copilot" button appears on the alert page. The same applies to Dependabot security alerts.

Test plan

  • CI passes on this PR (all lint, build, Trivy, gitleaks checks)
  • After merge, confirm auto-tag.yml does not create a duplicate tag (v2.1.1 already exists)
  • On next version bump PR, confirm tag is created and release.yml fires

🤖 Generated with Claude Code

https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5

Pin every GitHub Action reference in lint.yml and release.yml to a
commit SHA instead of a mutable tag — prevents supply chain attacks via
tag mutation. Versions pinned:

  actions/checkout        v7.0.1  3d3c42e
  ludeeus/action-shellcheck 2.0.0 00cae50  (was @master)
  hadolint/hadolint-action v3.5.0 06be81b  (was v3.3.0, matches PR #33)
  docker/setup-qemu-action v4.3.0 1f40c72
  docker/setup-buildx-action v4.3.0 37fe631
  docker/login-action     v4.6.0  dbcb813  (was @v4, matches PR #31 + newer)
  docker/metadata-action  v6.2.0  dc80280
  docker/build-push-action v7.3.0 53b7df9
  gitleaks/gitleaks-action v3     e0c47f4
  softprops/action-gh-release v3.0.3 e598afb (was v3.0.0, matches PR #34)

Also adds auto-tag.yml: on push to main, reads the semver from
synology/INFO and creates a matching vMAJOR.MINOR.PATCH tag if absent.
This makes the release workflow (release.yml) trigger automatically on
version bumps rather than requiring a manual tag push.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/actions/checkout 3d3c42e5aac5ba805825da76410c181273ba90b1 🟢 7
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1022 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Packaging⚠️ -1packaging workflow not detected
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 9security policy file detected
SAST🟢 10SAST tool is run on all commits
Branch-Protection🟢 6branch protection is not maximal on development and all release branches
actions/docker/build-push-action 53b7df96c91f9c12dcc8a07bcb9ccacbed38856a 🟢 7.5
Details
CheckScoreReason
Security-Policy🟢 9security policy file detected
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 1030 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases⚠️ -1no releases found
License🟢 10license file detected
Packaging🟢 10packaging workflow detected
Pinned-Dependencies🟢 7dependency not pinned by hash detected -- score normalized to 7
SAST🟢 9SAST tool detected but not run on all commits
actions/docker/login-action dbcb813823bdd20940b903addbd779551569679f 🟢 8.5
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 9security policy file detected
Code-Review🟢 10all changesets reviewed
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Pinned-Dependencies🟢 6dependency not pinned by hash detected -- score normalized to 6
Packaging🟢 10packaging workflow detected
SAST🟢 9SAST tool detected but not run on all commits
actions/docker/metadata-action dc802804100637a589fabce1cb79ff13a1411302 🟢 8.6
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
Security-Policy🟢 9security policy file detected
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Pinned-Dependencies🟢 7dependency not pinned by hash detected -- score normalized to 7
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
actions/docker/setup-buildx-action 37fe631027851001ddb9b187196cc803df7f5f0e 🟢 8.6
Details
CheckScoreReason
Security-Policy🟢 9security policy file detected
Code-Review🟢 10all changesets reviewed
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 1030 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases⚠️ -1no releases found
Pinned-Dependencies🟢 7dependency not pinned by hash detected -- score normalized to 7
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
actions/docker/setup-qemu-action 1f40c72289eff860ee54a304f1438e3cff362e0a 🟢 8.4
Details
CheckScoreReason
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 9security policy file detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Pinned-Dependencies🟢 5dependency not pinned by hash detected -- score normalized to 5
SAST🟢 10SAST tool is run on all commits
actions/softprops/action-gh-release e598afbe1493e6b1bafb1f389cabb956eab91231 🟢 5.5
Details
CheckScoreReason
Code-Review⚠️ 0Found 1/15 approved changesets -- score normalized to 0
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 10all dependencies are pinned
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Security-Policy⚠️ 0security policy file not detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • .github/workflows/release.yml

Doug Eubanks and others added 2 commits September 9, 2026 22:25
hadolint v3.5.0 (via hadolint-action v3.5.0) flags shell-form HEALTHCHECK
CMD with DL3025. Switch to JSON array notation, which is the preferred
form and avoids an implicit /bin/sh wrapper. The redundant || exit 1 is
dropped — sys.exit() already controls the exit code, and an unhandled
exception in the urlopen call also produces a non-zero exit.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5
Documentation, README, workflow-only, and asset-only merges to main
should not trigger a release check. Add path filters to auto-tag.yml
so the job only runs when synology/INFO, CHANGELOG.md, backup scripts,
docker files, or tests change — the files that actually accompany a
version bump.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5
@RealDougEubanks
RealDougEubanks merged commit 2387231 into main Sep 10, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant