Repository navigation
ci: harden the release supply chain - #108
Merged
Merged
Conversation
- Attest released images with SLSA provenance, an SPDX SBOM and a keyless cosign signature, and require npm provenance on publish. - Deny workflow token permissions by default, each job granting only what it uses. The docker build jobs no longer get attestations/id-token, which only the attest job needs. - Don't persist the job token after checkout, and pass SonarQube only its own secrets instead of inheriting all of them. - Pin actions and reusable workflows to commit SHAs and the bun base images to digests, kept up to date by Renovate, and install bun from mise.toml in the Docker tests. - Read vulnerability alerts from OSV in Renovate.
Contributor
|
🤖 Hey ! ✅ Gitleaks found no leaked secrets in the git history. The secret scan report for the current pull request is available in the GitHub Security Tab. |
Contributor
|
🤖 Hey ! The security scan report for the current pull request is available in the GitHub Security Tab. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Supply-chain hardening for the release artifacts and the workflows.
Release artifacts
Docker image: new
attestjob in CD (sharedattest-docker.yml) giving each released image:The published v0.13.1 image has none of these today (
gh attestation verifyreturns 404).npm package:
PROVENANCE: trueonrelease-npm. Trusted publishing already attaches SLSA provenance (v0.13.1 has it); this makes the release fail if that ever stops.Workflow hardening
permissions: {}and each job grants only what it uses. Grants were checked against what each shared workflow's jobs request at the pinned commit: nothing missing, nothing extra.attestations: write/id-token: write, whichbuild-docker.ymlnever uses. Only the newattestjob has them.persist-credentials: false, so the job token isn't left in.git/configwhile dependencies and tests run.SONAR_TOKENandSONAR_PROJECT_KEYonly, instead ofsecrets: inherit.Pinning
v0.35.0).oven/bunpinned by digest in the Dockerfile.mise.tomlinstead oflatest.helpers:pinGitHubActionDigestsanddocker:pinDigestspresets;bungroup.Vulnerability alerts
osvVulnerabilityAlerts). ItsvulnerabilityAlertsconfig was a no-op, since Dependabot alerts are disabled on the repository.Verification
renovate-config-validatorpass.self-repositoryhints remain, suggesting the newer$/syntax for local workflows.Notes
attestjob only runs on the next release. Once it has, check it with:gh attestation verify oci://ghcr.io/this-is-tobi/docpress:<version> --repo this-is-tobi/docpresscosign verify ghcr.io/this-is-tobi/docpress:<version> --certificate-identity-regexp 'https://github.com/this-is-tobi/' --certificate-oidc-issuer https://token.actions.githubusercontent.com