Skip to content

fix(security): CI/CD command injection + supply chain hardening#1

Open
riaworks wants to merge 1 commit intomainfrom
fix/cicd-security-hardening
Open

fix(security): CI/CD command injection + supply chain hardening#1
riaworks wants to merge 1 commit intomainfrom
fix/cicd-security-hardening

Conversation

@riaworks
Copy link
Owner

Summary

  • C-01: Fix command injection via PR comment interpolation (env: blocks)
  • M-01: Pin TruffleHog to v3.88.22
  • L-01: Pin all GitHub Actions to commit SHAs
  • L-02: Pin CLI version
  • L-08: Document workflow purposes

Clean re-application after fork recreation.

…ICAL]

CRITICAL SECURITY FIX:
- C-01: Fix command injection via PR comment interpolation (env: blocks)
- M-01: Pin TruffleHog to v3.88.22
- L-01: Pin all GitHub Actions to commit SHAs
- L-02: Pin CLI version
- L-08: Document workflow purposes

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant