T08 · Insecure Dependencies
- Location
SKILL.md:116- Finding
Mutable Third-Party GitHub Actions and Docker Image References
- Content
View full analysis
- Remediation
View remediation
# stable at review time - uses: Swatinem/rust-cache@ # v2 - uses: softprops/action-gh-release@ # v2 ``` Apply the same approach to the Docker, tmate, and paths-filter Actions. 2. Pin Docker images by immutable digest instead of `latest`: ```bash docker run --rm \ -v "$(pwd):/repo" \ -w /repo \ rhysd/actionlint@sha256: ``` 3. Use controlled dependency-update automation, such as Dependabot or Renovate, to propose reviewed SHA and digest updates. Require code-owner approval for workflow changes. 4. Configure minimal workflow permissions globally and elevate them only in jobs that require additional access: ```yaml permissions: contents: read ``` Grant `packages: write`, `contents: write`, or other elevated capabilities only to narrowly scoped publishing jobs. 5. Avoid exposing secrets to third-party Actions unless necessary. Prefer GitHub OpenID Connect and short-lived credentials over long-lived deployment tokens where supported. 6. Protect release and production environments with required reviewers, branch restrictions, and deployment approval rules. 7. For interactive debugging Actions, retain actor restrictions, pin the Action to an immutable SHA, set a short job timeout, and ensure production secrets are unavailable to the debugging job. 8. Add policy enforcement, such as actionlint plus an organization policy or security scanner, that rejects unpinned `uses:` references and Docker images without digests. ]]>
