Skip to content

ci: harden the release supply chain - #108

Merged
this-is-tobi merged 1 commit into
mainfrom
ci/supply-chain-hardening
Sep 30, 2026
Merged

this-is-tobi merged 1 commit into
mainfrom
ci/supply-chain-hardening

Conversation

@this-is-tobi

Copy link
Copy Markdown
Owner

Summary

Supply-chain hardening for the release artifacts and the workflows.

Release artifacts

  • Docker image: new attest job in CD (shared attest-docker.yml) giving each released image:

    • SLSA build provenance (GitHub attestation);
    • an SPDX SBOM (Trivy) attached as a cosign attestation;
    • a keyless cosign signature.

    The published v0.13.1 image has none of these today (gh attestation verify returns 404).

  • npm package: PROVENANCE: true on release-npm. Trusted publishing already attaches SLSA provenance (v0.13.1 has it); this makes the release fail if that ever stops.

Workflow hardening

  • Token permissions: every workflow starts from permissions: {} and each job grants only what it uses. Grants were checked against what each shared workflow's jobs request at the pinned commit: nothing missing, nothing extra.
  • docker build jobs (CI and CD): no longer get attestations: write / id-token: write, which build-docker.yml never uses. Only the new attest job has them.
  • Checkouts: persist-credentials: false, so the job token isn't left in .git/config while dependencies and tests run.
  • SonarQube: receives SONAR_TOKEN and SONAR_PROJECT_KEY only, instead of secrets: inherit.

Pinning

  • Actions and shared workflows: pinned to commit SHAs with a version comment (shared workflows at v0.35.0).
  • Base images: oven/bun pinned by digest in the Dockerfile.
  • Docker tests: install bun from mise.toml instead of latest.
  • Renovate keeps the pins up to date:
    • helpers:pinGitHubActionDigests and docker:pinDigests presets;
    • digest-only updates join the non-major group;
    • the bun Docker image joins the bun group.

Vulnerability alerts

  • Renovate reads vulnerabilities from OSV (osvVulnerabilityAlerts). Its vulnerabilityAlerts config was a no-op, since Dependabot alerts are disabled on the repository.

Verification

  • actionlint, ESLint and renovate-config-validator pass.
  • zizmor: no medium or high findings. Two low self-repository hints remain, suggesting the newer $/ syntax for local workflows.
  • A local Docker build with the digest-pinned base images works, and the image runs.

Notes

  • The attest job only runs on the next release. Once it has, check it with:
    • gh attestation verify oci://ghcr.io/this-is-tobi/docpress:<version> --repo this-is-tobi/docpress
    • cosign verify ghcr.io/this-is-tobi/docpress:<version> --certificate-identity-regexp 'https://github.com/this-is-tobi/' --certificate-oidc-issuer https://token.actions.githubusercontent.com
  • Repository settings to switch on separately:
    • Dependabot alerts;
    • CodeQL default setup, which also analyses the workflows.

- Attest released images with SLSA provenance, an SPDX SBOM and a keyless cosign signature,
  and require npm provenance on publish.
- Deny workflow token permissions by default, each job granting only what it uses. The docker
  build jobs no longer get attestations/id-token, which only the attest job needs.
- Don't persist the job token after checkout, and pass SonarQube only its own secrets instead
  of inheriting all of them.
- Pin actions and reusable workflows to commit SHAs and the bun base images to digests, kept up
  to date by Renovate, and install bun from mise.toml in the Docker tests.
- Read vulnerability alerts from OSV in Renovate.
@github-actions

Copy link
Copy Markdown
Contributor

🤖 Hey !

✅ Gitleaks found no leaked secrets in the git history. The secret scan report for the current pull request is available in the GitHub Security Tab.

Comment thread Dockerfile Dismissed
@github-actions

Copy link
Copy Markdown
Contributor

🤖 Hey !

The security scan report for the current pull request is available in the GitHub Security Tab.

@this-is-tobi
this-is-tobi merged commit 172806c into main Sep 30, 2026
24 checks passed
@this-is-tobi
this-is-tobi deleted the ci/supply-chain-hardening branch September 30, 2026 20:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants