ci: pin action SHAs and add auto-tag release workflow - #36
Merged
Merged
Conversation
Pin every GitHub Action reference in lint.yml and release.yml to a commit SHA instead of a mutable tag — prevents supply chain attacks via tag mutation. Versions pinned: actions/checkout v7.0.1 3d3c42e ludeeus/action-shellcheck 2.0.0 00cae50 (was @master) hadolint/hadolint-action v3.5.0 06be81b (was v3.3.0, matches PR #33) docker/setup-qemu-action v4.3.0 1f40c72 docker/setup-buildx-action v4.3.0 37fe631 docker/login-action v4.6.0 dbcb813 (was @v4, matches PR #31 + newer) docker/metadata-action v6.2.0 dc80280 docker/build-push-action v7.3.0 53b7df9 gitleaks/gitleaks-action v3 e0c47f4 softprops/action-gh-release v3.0.3 e598afb (was v3.0.0, matches PR #34) Also adds auto-tag.yml: on push to main, reads the semver from synology/INFO and creates a matching vMAJOR.MINOR.PATCH tag if absent. This makes the release workflow (release.yml) trigger automatically on version bumps rather than requiring a manual tag push. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
hadolint v3.5.0 (via hadolint-action v3.5.0) flags shell-form HEALTHCHECK CMD with DL3025. Switch to JSON array notation, which is the preferred form and avoids an implicit /bin/sh wrapper. The redundant || exit 1 is dropped — sys.exit() already controls the exit code, and an unhandled exception in the urlopen call also produces a non-zero exit. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5
Documentation, README, workflow-only, and asset-only merges to main should not trigger a release check. Add path filters to auto-tag.yml so the job only runs when synology/INFO, CHANGELOG.md, backup scripts, docker files, or tests change — the files that actually accompany a version bump. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5
This was referenced Sep 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
uses:line inlint.ymlandrelease.ymlis now pinned to a commit SHA instead of a mutable tag (e.g.@v4→@sha256), closing the supply chain attack surface where a tag could be repointed to malicious code.hadolint/hadolint-actionto v3.5.0 (supersedes Dependabot PR ci: bump hadolint/hadolint-action from 3.3.0 to 3.5.0 #33),docker/login-actionto v4.6.0 (supersedes PR ci: bump docker/login-action from 4 to 4.5.2 #31), andsoftprops/action-gh-releaseto v3.0.3 (supersedes PR ci: bump softprops/action-gh-release from 3.0.0 to 3.0.3 #34).auto-tag.yml): on every push to main, reads the semver fromsynology/INFO, and if no matchingvMAJOR.MINOR.PATCHtag exists, creates and pushes it. This triggers the existingrelease.ymlautomatically — the release flow is now: bump version insynology/INFO+CHANGELOG.md→ merge PR → tag created → Docker multi-arch image pushed → GitHub Release published.Copilot Autofix note
Copilot Autofix for CodeQL alerts is automatically enabled on public repos — no workflow change needed. When CodeQL opens an alert, a "Fix with Copilot" button appears on the alert page. The same applies to Dependabot security alerts.
Test plan
🤖 Generated with Claude Code
https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5