Skip to content

ci: harden Socket supply-chain dependencies - #6

Merged
mxnstrexgl merged 1 commit into
mainfrom
agent/socket-supply-chain-hardening
Jul 27, 2026
Merged

ci: harden Socket supply-chain dependencies#6
mxnstrexgl merged 1 commit into
mainfrom
agent/socket-supply-chain-hardening

Conversation

@mxnstrexgl

Copy link
Copy Markdown
Owner

What changed

  • pin actions/checkout and TruffleHog to immutable, verified release SHAs
  • restrict the workflow token to read-only repository contents
  • disable persisted checkout credentials in every job
  • pin Safety CLI to 3.8.1
  • replace the stale tfsec-action integration with pinned Trivy configuration scanning

Why

Socket identified supply-chain risk in mutable and outdated CI dependencies. This removes moving action references and reduces workflow credential exposure without changing application code.

Validation

  • branch is one commit ahead of main
  • only .github/workflows/ci.yml changed
  • GitHub-hosted workflow checks will validate the updated workflow

@mxnstrexgl
mxnstrexgl marked this pull request as ready for review July 27, 2026 10:00
@mxnstrexgl
mxnstrexgl merged commit d3816c2 into main Jul 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant