mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-24 17:36:42 +00:00
ci: harden supply chain (SHA pin actions, least-privilege permissions) (#475)
Pin three third-party actions to full commit SHAs with version comments so dependabot can update them in place without exposing the pipeline to upstream tag tampering: - aquasecurity/trivy-action@v0.35.0 - peter-evans/create-pull-request@v8.1.1 - googleapis/release-please-action@v4.4.0 Add a workflow-level permissions: contents: read default to ci.yml, with update-screenshots keeping its explicit contents: write + pull-requests: write override. Add the same default to docker-publish.yml (single job). Expand .dockerignore to explicitly exclude .env*, *.key, *.pem, .github/, docs/, website/, e2e/, tests/, test-results/, and playwright-report/ as defense in depth against accidental build-context leaks. None of these paths are read by any COPY step in Dockerfile.
This commit is contained in:
@@ -15,6 +15,8 @@ jobs:
|
||||
name: Push Docker image to Docker Hub
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 30
|
||||
permissions:
|
||||
contents: read
|
||||
steps:
|
||||
- name: Check out the repo
|
||||
uses: actions/checkout@v6
|
||||
|
||||
Reference in New Issue
Block a user