Repository navigation
chore: Cherry-pick changes from upstream - #38
Conversation
Signed-off-by: Anurag Rajawat <anurag@stepsecurity.io>
06ca78d to
a748317
Compare
Signed-off-by: Anurag Rajawat <anurag@stepsecurity.io>
|
📦 Target Release Version: |
🔍 Cherry-Pick Verification Report📦 Upstream Changes: 📋 File-by-File Analysis:
|
|
test comment - please approve |
|
PR Review Action Type Passed Checks
Failed Checks None. All mandatory checks passed. Warnings
Security Findings
Summary The cherry-pick from akhilerm/tag-push-action v2.2.0 to v2.3.0 is well-structured. The refactor to src/index.ts entrypoint, removal of the bare run() call in main.ts, and dependency upgrades are all clean. The main concern before release: the inner repo-copy Docker image tag still says v2.2.0 while the action is at v2.3.0; publish a new image and update the reference in src/main.ts. |
| - name: Start authenticated registry | ||
| run: | | ||
| mkdir -p "$RUNNER_TEMP/auth" | ||
| docker run --rm --entrypoint htpasswd httpd:2 \ |
There was a problem hiding this comment.
Supply-chain risk: httpd:2 is not pinned to a SHA digest. A compromised or updated image could silently affect CI runs. Pin it to a specific digest, e.g.:
| docker run --rm --entrypoint htpasswd httpd:2 \ | |
| docker run --rm --entrypoint htpasswd httpd:2.4.62@sha256:<digest> \ |
Run docker pull httpd:2 && docker inspect httpd:2 --format='{{index .RepoDigests 0}}' to get the current digest.
| run: npm install | ||
|
|
||
| - name: Test | ||
| run: npm test No newline at end of file |
There was a problem hiding this comment.
Missing newline at end of file — the last line of ci.yml has no trailing newline (\ No newline at end of file in the diff). Add a newline after npm test.
| -e REGISTRY_AUTH=htpasswd \ | ||
| -e "REGISTRY_AUTH_HTPASSWD_REALM=Registry Realm" \ | ||
| -e REGISTRY_AUTH_HTPASSWD_PATH=/auth/htpasswd \ | ||
| docker.io/distribution/distribution:3 |
There was a problem hiding this comment.
Supply-chain risk: docker.io/distribution/distribution:3 is not pinned to a SHA digest. Pin it to a specific digest to prevent silent image substitution in CI.
| } | ||
|
|
||
| async function run(): Promise<void> { | ||
| export async function run(): Promise<void> { |
There was a problem hiding this comment.
Docker image version mismatch inside this function: At line 82, the exec.exec call references ghcr.io/step-security/tag-push-action/repo-copy:v2.2.0@sha256:d91abc5f55fc4124afabc7f6899fd4e3870d0e2d1747ef3763783c80f3eb6828. This PR bumps the action to v2.3.0 but the image tag is still v2.2.0. The SHA pin keeps it functionally safe, but the tag should be updated for semantic consistency. Publish repo-copy:v2.3.0 via the docker.yml workflow and update both the tag and digest here before release.
akhilerm/tag-push-action@v2.2.0...v2.3.0