Skip to content

chore: Cherry-pick changes from upstream - #38

Merged
anurag-stepsecurity merged 2 commits into
mainfrom
auto-cherry-pick
Aug 29, 2026
Merged

anurag-stepsecurity merged 2 commits into
mainfrom
auto-cherry-pick

Conversation

@anurag-stepsecurity

Copy link
Copy Markdown
Contributor

Signed-off-by: Anurag Rajawat <anurag@stepsecurity.io>
Signed-off-by: Anurag Rajawat <anurag@stepsecurity.io>
@anurag-stepsecurity

Copy link
Copy Markdown
Contributor Author

📦 Target Release Version: v2.3.0
📋 Previous Release Version: v2.2.0

@github-actions

Copy link
Copy Markdown
Contributor

🔍 Cherry-Pick Verification Report

📦 Upstream Changes: v2.2.0...v2.3.0

📋 File-by-File Analysis:

.github/dependabot.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+8 -3)

.github/workflows/ci.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+89 -49) | Missing 40 additions | Missing 49 deletions

README.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+7 -7)

action.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+1 -1)

src/index.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+7 -0)

src/main.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All upstream changes applied (+1 -3) with 2 additional changes

📊 Summary:

  • Total files changed upstream: 6
  • Files present in PR: 3/6
  • Files with matching changes: 2/6

❌ Overall Status: 🔴 INCOMPLETE - Missing files or changes

@github-actions

Copy link
Copy Markdown
Contributor

test comment - please approve

@github-actions

Copy link
Copy Markdown
Contributor

PR Review

Action Type
Node-based action. Uses node24 runtime with dist/index.js as entry point (src/index.ts to src/main.ts).


Passed Checks

  • License: Dual copyright present (original GitHub contributors + StepSecurity).
  • action.yml: Present, author is step-security.
  • SECURITY.md: Present.
  • FUNDING.yml: Not present (correct).
  • Workflows: auto_cherry_pick.yml and actions_release.yml both present in .github/workflows.
  • renovate.json: Not present (correct).
  • PULL_REQUEST.md: Not present (correct).
  • ISSUE_TEMPLATE folder: Not present (correct).
  • CHANGELOG.md: Not present (correct).
  • .vscode folder: Not present (correct).
  • README semver tags: All examples use major version only (@v2), not full semver.
  • README banner: StepSecurity Maintained Action banner is present.
  • Subscription URL: Correct (agent.api.stepsecurity.io endpoint used).
  • Upstream variable: akhilerm/tag-push-action matches original-owner + repo-name in auto_cherry_pick.yml.
  • package.json author: step-security.
  • package.json repository: URL contains step-security.
  • Build script: Present in package.json.
  • dist folder: Present.

Failed Checks

None. All mandatory checks passed.


Warnings

  • Docker image version mismatch: src/main.ts references repo-copy:v2.2.0 (SHA-pinned) but the action is bumping to v2.3.0. Functionally safe due to digest pin, but semantically stale. Publish repo-copy:v2.3.0 via docker.yml and update the reference in src/main.ts.
  • Unpinned CI images: httpd:2 and docker.io/distribution/distribution:3 in ci.yml have no SHA digest pins. Test-only images, no impact on action users, but introduce supply-chain risk to the build pipeline.
  • Missing trailing newline in ci.yml.

Security Findings

  • Low-severity (CI/test-only): httpd:2 and distribution:3 in .github/workflows/ci.yml are not SHA-pinned. A compromised upstream tag could affect CI runs. Not exploitable by action users.
  • No vulnerabilities in the action runtime code itself. Subscription check URL correct, Docker image is SHA-pinned, event file parsing is safe.

Summary

The cherry-pick from akhilerm/tag-push-action v2.2.0 to v2.3.0 is well-structured. The refactor to src/index.ts entrypoint, removal of the bare run() call in main.ts, and dependency upgrades are all clean. The main concern before release: the inner repo-copy Docker image tag still says v2.2.0 while the action is at v2.3.0; publish a new image and update the reference in src/main.ts.

Comment thread .github/workflows/ci.yml
- name: Start authenticated registry
run: |
mkdir -p "$RUNNER_TEMP/auth"
docker run --rm --entrypoint htpasswd httpd:2 \

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Supply-chain risk: httpd:2 is not pinned to a SHA digest. A compromised or updated image could silently affect CI runs. Pin it to a specific digest, e.g.:

Suggested change
docker run --rm --entrypoint htpasswd httpd:2 \
docker run --rm --entrypoint htpasswd httpd:2.4.62@sha256:<digest> \

Run docker pull httpd:2 && docker inspect httpd:2 --format='{{index .RepoDigests 0}}' to get the current digest.

Comment thread .github/workflows/ci.yml
run: npm install

- name: Test
run: npm test No newline at end of file

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing newline at end of file — the last line of ci.yml has no trailing newline (\ No newline at end of file in the diff). Add a newline after npm test.

Comment thread .github/workflows/ci.yml
-e REGISTRY_AUTH=htpasswd \
-e "REGISTRY_AUTH_HTPASSWD_REALM=Registry Realm" \
-e REGISTRY_AUTH_HTPASSWD_PATH=/auth/htpasswd \
docker.io/distribution/distribution:3

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Supply-chain risk: docker.io/distribution/distribution:3 is not pinned to a SHA digest. Pin it to a specific digest to prevent silent image substitution in CI.

Comment thread src/main.ts
}

async function run(): Promise<void> {
export async function run(): Promise<void> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Docker image version mismatch inside this function: At line 82, the exec.exec call references ghcr.io/step-security/tag-push-action/repo-copy:v2.2.0@sha256:d91abc5f55fc4124afabc7f6899fd4e3870d0e2d1747ef3763783c80f3eb6828. This PR bumps the action to v2.3.0 but the image tag is still v2.2.0. The SHA pin keeps it functionally safe, but the tag should be updated for semantic consistency. Publish repo-copy:v2.3.0 via the docker.yml workflow and update both the tag and digest here before release.

@anurag-stepsecurity
anurag-stepsecurity merged commit 36237e7 into main Aug 29, 2026
14 checks passed
@anurag-stepsecurity
anurag-stepsecurity deleted the auto-cherry-pick branch August 29, 2026 06:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants