From 35e0ce4809cbc9beea9ab6b1a6e9ca8b90535270 Mon Sep 17 00:00:00 2001 From: nscuro Date: Wed, 23 Sep 2026 12:13:49 +0200 Subject: [PATCH 1/7] chore: disable credential persistence for actions/checkout Addresses zizmor `artipacked` findings. Signed-off-by: nscuro --- .github/workflows/build.yaml | 4 ++++ .github/workflows/release.yaml | 6 ++++++ 2 files changed, 10 insertions(+) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index d046e95..4dba04b 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -14,6 +14,8 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3 + with: + persist-credentials: false - name: Run golangci-lint uses: reviewdog/action-golangci-lint@f9bba13753278f6a73b27a56a3ffb1bfda90ed71 # v2 @@ -26,6 +28,8 @@ jobs: steps: - name: Checkout source code uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3 + with: + persist-credentials: false - name: Setup Go uses: actions/setup-go@be3c94b385c4f180051c996d336f57a34c397495 # v3 diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 2043993..b6b1971 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -25,6 +25,8 @@ jobs: steps: - name: Checkout uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 + with: + persist-credentials: false - name: Set up Go uses: actions/setup-go@be3c94b385c4f180051c996d336f57a34c397495 # v3 @@ -47,6 +49,8 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 + with: + persist-credentials: false # - name: Extract metadata (tags, labels) for Docker # id: meta @@ -107,6 +111,8 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 + with: + persist-credentials: false - name: Set up Helm uses: azure/setup-helm@1a275c3b69536ee54be43f2070a358922e12c8d4 # v4 From 7213d30d7000d0f157a1b86730b5bc77f9ccb0a9 Mon Sep 17 00:00:00 2001 From: nscuro Date: Wed, 23 Sep 2026 12:19:48 +0200 Subject: [PATCH 2/7] chore: pin trivy action to digest Closes #44 Signed-off-by: nscuro --- .github/workflows/build.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 4dba04b..4e3845c 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -58,7 +58,7 @@ jobs: docker build -t controlplane/netassert:${{ github.sha }} . - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@master + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # tag=v0.36.0 with: image-ref: 'controlplane/netassert:${{ github.sha }}' format: 'table' From be20603d46937296e7ca672e98513fcc75a43ae6 Mon Sep 17 00:00:00 2001 From: nscuro Date: Wed, 23 Sep 2026 12:38:50 +0200 Subject: [PATCH 3/7] chore: downscope github actions permissions Addresses zizmor's `excessive-permissions` findings by scoping permissions to jobs, and explicitly dropping permissions at the workflow-level. Also drops `contents: read` and `pull-requests: read` permissions entirely, since neither is required for public repositories like this one. The `attestations: write` permission was unused and thus also dropped entirely. Signed-off-by: nscuro --- .github/workflows/build.yaml | 4 ++++ .github/workflows/release.yaml | 13 ++++++++----- 2 files changed, 12 insertions(+), 5 deletions(-) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 4e3845c..d1e1208 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -8,9 +8,13 @@ on: pull_request: branches: ['main', 'master'] +permissions: {} + jobs: lint: runs-on: ubuntu-latest + permissions: + checks: write # Required for reviewdog to create check runs. steps: - name: Checkout repository uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3 diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index b6b1971..874d9a0 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -6,11 +6,7 @@ on: - "v[0-9]+.[0-9]+.[0-9]+" - "v[0-9]+.[0-9]+.[0-9]+-testing[0-9]+" -permissions: - contents: write - packages: write - id-token: write - attestations: write +permissions: {} env: GH_REGISTRY: ghcr.io @@ -22,6 +18,8 @@ env: jobs: goreleaser: runs-on: ubuntu-latest + permissions: + contents: write # Required for GoReleaser to create releases and upload assets. steps: - name: Checkout uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5 @@ -45,6 +43,9 @@ jobs: docker: runs-on: ubuntu-latest + permissions: + id-token: write # Required for keyless signing with cosign. + packages: write # Required to push images to ghcr.io. steps: - name: Checkout repository @@ -107,6 +108,8 @@ jobs: helm: runs-on: ubuntu-latest + permissions: + packages: write # Required to push chart to ghcr.io. steps: - name: Checkout repository From 512671c0782647e6e9d9f4408e50bdd58fee8a23 Mon Sep 17 00:00:00 2001 From: nscuro Date: Wed, 23 Sep 2026 12:43:56 +0200 Subject: [PATCH 4/7] chore: address zizmor template-injection findings Prevents template injection through interpolation of expressions by defining env vars with their respective values, as per https://docs.zizmor.sh/audits/#remediation_30. Also refactors `${{ env. }}` expressions to their `${}` shell equivalents as per the same zizmor guidance. Signed-off-by: nscuro --- .github/workflows/release.yaml | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 874d9a0..6caf199 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -100,11 +100,13 @@ jobs: SNIFFER_IMG_VERSION=${{ env.SNIFFER_IMG_VERSION }} - name: Sign artifact + env: + DIGEST: ${{ steps.buildpush.outputs.digest }} run: | cosign sign --yes \ - "${{ env.GH_REGISTRY }}/${{ env.IMAGE_NAME }}@${{ steps.buildpush.outputs.digest }}" + "${GH_REGISTRY}/${IMAGE_NAME}@${DIGEST}" cosign sign --yes \ - "docker.io/controlplane/netassert@${{ steps.buildpush.outputs.digest }}" + "docker.io/controlplane/netassert@${DIGEST}" helm: runs-on: ubuntu-latest @@ -124,8 +126,10 @@ jobs: uses: mikefarah/yq@065b200af9851db0d5132f50bc10b1406ea5c0a8 # v4 - name: Log in to GitHub Container Registry + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | - echo "${{ secrets.GITHUB_TOKEN }}" | helm registry login ghcr.io -u ${{ github.actor }} --password-stdin + echo "${GITHUB_TOKEN}" | helm registry login ghcr.io -u "${GITHUB_ACTOR}" --password-stdin - name: Prepare and package Helm chart run: | From 1fd45fc519a971670c5a23c0e39d12e1b2a3c774 Mon Sep 17 00:00:00 2001 From: nscuro Date: Wed, 23 Sep 2026 12:46:58 +0200 Subject: [PATCH 5/7] chore: explicitly disable cache for actions/setup-go Addresses zizmor's `cache-poisoning` findings. Note that this is practically a no-op for now because `v3` of the action has caching turned off by default: https://github.com/actions/setup-go/tree/v3#caching-dependency-files-and-build-outputs Signed-off-by: nscuro --- .github/workflows/build.yaml | 1 + .github/workflows/release.yaml | 1 + 2 files changed, 2 insertions(+) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index d1e1208..42abd87 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -39,6 +39,7 @@ jobs: uses: actions/setup-go@be3c94b385c4f180051c996d336f57a34c397495 # v3 with: go-version-file: 'go.mod' + cache: false - name: Install dependencies run: go get ./... diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 6caf199..f9c9d94 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -30,6 +30,7 @@ jobs: uses: actions/setup-go@be3c94b385c4f180051c996d336f57a34c397495 # v3 with: go-version-file: 'go.mod' + cache: false - uses: anchore/sbom-action/download-syft@f8bdd1d8ac5e901a77a92f111440fdb1b593736b # v0.20.6 From b288dce3eb23023515fa6fca7ba0cbd49e501aa2 Mon Sep 17 00:00:00 2001 From: nscuro Date: Wed, 23 Sep 2026 12:50:24 +0200 Subject: [PATCH 6/7] chore: add lint workflow for github actions Signed-off-by: nscuro --- .github/workflows/lint_gha.yaml | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) create mode 100644 .github/workflows/lint_gha.yaml diff --git a/.github/workflows/lint_gha.yaml b/.github/workflows/lint_gha.yaml new file mode 100644 index 0000000..3a4bc5c --- /dev/null +++ b/.github/workflows/lint_gha.yaml @@ -0,0 +1,32 @@ +name: Lint GitHub Actions + +on: + push: + branches: [master] + paths: + - ".github/workflows/*.yaml" + - ".github/dependabot.yaml" + pull_request: + branches: [master] + paths: + - ".github/workflows/*.yaml" + - ".github/dependabot.yaml" + +permissions: {} + +jobs: + lint-gha: + name: Lint GitHub Actions + timeout-minutes: 5 + runs-on: ubuntu-latest + permissions: + security-events: write + contents: read + actions: read + steps: + - name: Checkout Repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # tag=v7.0.1 + with: + persist-credentials: false + - name: Run zizmor + uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4 From 1c964872ade6a827d99576bfea9c97f9c5f6ffc6 Mon Sep 17 00:00:00 2001 From: nscuro Date: Thu, 24 Sep 2026 17:29:13 +0200 Subject: [PATCH 7/7] chore: strip tag= prefix from actions digest comments To be consistent with existing comments. Signed-off-by: nscuro --- .github/workflows/build.yaml | 2 +- .github/workflows/lint_gha.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 42abd87..29f6995 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -63,7 +63,7 @@ jobs: docker build -t controlplane/netassert:${{ github.sha }} . - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # tag=v0.36.0 + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0 with: image-ref: 'controlplane/netassert:${{ github.sha }}' format: 'table' diff --git a/.github/workflows/lint_gha.yaml b/.github/workflows/lint_gha.yaml index 3a4bc5c..7490fad 100644 --- a/.github/workflows/lint_gha.yaml +++ b/.github/workflows/lint_gha.yaml @@ -25,7 +25,7 @@ jobs: actions: read steps: - name: Checkout Repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # tag=v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Run zizmor