T08 · Insecure Dependencies
- Location
assets/github-actions-build.yml:19- Finding
GitHub Actions Dependencies Are Referenced by Mutable Version Tags
- Content
View full analysis
- Remediation
View remediation
- uses: docker/setup-buildx-action@ - uses: docker/login-action@ - uses: docker/metadata-action@ - uses: docker/build-push-action@ ``` 2. Retain the human-readable release version in a comment: ```yaml - uses: actions/checkout@ # v4.x ``` 3. Apply the same pinning to all workflows embedded in examples and reference documents so generated files do not reintroduce mutable dependencies. 4. Configure Dependabot or Renovate to propose SHA updates through pull requests. Require review of release notes and commit differences before merging updates. 5. Preserve minimal job permissions and split image publication from untrusted build operations where practical. 6. Consider artifact signing and provenance generation for published images, and configure deployment systems to verify signatures or attestations before deployment. 7. Prefer immutable image references, such as digests or commit-derived tags, over `latest` for production deployment. ]]>
