Skip to content

ci: harden Package workflow against supply-chain and injection risks - #2596

Merged
blowekamp merged 3 commits into
SimpleITK:mainfrom
blowekamp:harden-package-workflow
May 14, 2026
Merged

blowekamp merged 3 commits into
SimpleITK:mainfrom
blowekamp:harden-package-workflow

Conversation

@blowekamp

Copy link
Copy Markdown
Member

Addresses three security issues identified in the Package workflow and associated composite actions.

Changes

Prevent shell injection via context expressions (publish job)
Context values (github.ref_name, steps.tag.outputs.name, etc.) were interpolated directly into bash scripts. They are now passed through intermediate env: variables, following GitHub's recommended practice.

Pin third-party actions to full commit SHAs
All actions/checkout, actions/setup-python, actions/upload-artifact, actions/download-artifact, and actions/cache references now use immutable commit SHAs instead of mutable version tags. Covers Package.yml and the three composite actions.

Fix VCVAR_OPTIONS interpolation in cmd shell (package_csharp, package_java, package_python)
${{ inputs.VCVAR_OPTIONS }} was written directly into cmd shell scripts. It is now passed via env: and referenced as %VCVAR_OPTIONS%.

Per GitHub Actions best practices, move context expressions
(github.ref_name, steps.tag.outputs.name, etc.) into intermediate
env: variables instead of interpolating them directly into shell
scripts in the publish job.
@blowekamp
blowekamp requested a review from zivy May 14, 2026 20:17

@zivy zivy left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Possibly add a comment next to each commit sha indicating what version it corresponds to and saying that the immutable commit sha is used to ensure security and that the version tag which is modifiable originally pointed to that commit?

@blowekamp

Copy link
Copy Markdown
Member Author

Possibly add a comment next to each commit sha indicating what version it corresponds to and saying that the immutable commit sha is used to ensure security and that the version tag which is modifiable originally pointed to that commit?

I just checked the docs: https://github.com/marketplace/actions/dependabot-sha-comment-action?version=v0.0.4

The version comment has to be on the same line for dependapot to do its things.

@blowekamp
blowekamp force-pushed the harden-package-workflow branch from 2fd5a6b to fc84a9e Compare May 14, 2026 20:49
@blowekamp
blowekamp merged commit d577bac into SimpleITK:main May 14, 2026
10 checks passed
@blowekamp
blowekamp deleted the harden-package-workflow branch September 9, 2026 12:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants