diff --git a/.github/workflows/code-coverage.yaml b/.github/workflows/code-coverage.yaml index 35092f7..6e4cf50 100644 --- a/.github/workflows/code-coverage.yaml +++ b/.github/workflows/code-coverage.yaml @@ -22,6 +22,12 @@ jobs: steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Install Socket Firewall + uses: SocketDev/action@ba6de6cc0565af1f42295590380973573297e31f # v1.3.2 + with: + mode: firewall-free + firewall-version: "1.15.1" + - name: Install pnpm uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 @@ -32,7 +38,7 @@ jobs: cache: 'pnpm' - name: Install Dependencies - run: pnpm install --frozen-lockfile + run: sfw pnpm install --frozen-lockfile - name: Build run: pnpm build diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 98c002f..3053fad 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -21,6 +21,12 @@ jobs: steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Install Socket Firewall + uses: SocketDev/action@ba6de6cc0565af1f42295590380973573297e31f # v1.3.2 + with: + mode: firewall-free + firewall-version: "1.15.1" + - name: Install pnpm uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 @@ -31,7 +37,7 @@ jobs: registry-url: 'https://registry.npmjs.org' - name: Install Dependencies - run: pnpm install --frozen-lockfile + run: sfw pnpm install --frozen-lockfile - name: Build run: pnpm build diff --git a/.github/workflows/tests.yaml b/.github/workflows/tests.yaml index c7e6143..a839416 100644 --- a/.github/workflows/tests.yaml +++ b/.github/workflows/tests.yaml @@ -26,6 +26,12 @@ jobs: steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Install Socket Firewall + uses: SocketDev/action@ba6de6cc0565af1f42295590380973573297e31f # v1.3.2 + with: + mode: firewall-free + firewall-version: "1.15.1" + - name: Install pnpm uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 @@ -36,7 +42,7 @@ jobs: cache: 'pnpm' - name: Install Dependencies - run: pnpm install --frozen-lockfile + run: sfw pnpm install --frozen-lockfile - name: Build run: pnpm build diff --git a/DEFENSE_IN_DEPTH.md b/DEFENSE_IN_DEPTH.md index 01287f1..baca76d 100644 --- a/DEFENSE_IN_DEPTH.md +++ b/DEFENSE_IN_DEPTH.md @@ -25,8 +25,8 @@ Profile: npm library · public ## 4. GitHub Actions - [x] `permissions: contents: read` (or `{}` + per-job grants) on every workflow — verified 2026-09-09 - [x] No `contents: write` except jobs whose purpose is mutating the repo (GitHub Release, Changesets version PR); generated output is a workflow artifact, never committed back from CI — verified 2026-09-09 -- [ ] Every action pinned to a full commit SHA (`npx actions-up`) (PR #69 pending) -- [ ] Every job installs Socket Firewall (`SocketDev/action` SHA-pinned, `firewall-version` pinned); `pnpm install` / `npm install` run as `sfw pnpm install` / `sfw npm install` +- [x] Every action pinned to a full commit SHA (`npx actions-up`) — PR #69 +- [ ] Every job installs Socket Firewall (`SocketDev/action` SHA-pinned, `firewall-version` pinned); `pnpm install` / `npm install` run as `sfw pnpm install` / `sfw npm install` (PR #70 pending) - [ ] `.github/workflows/check-workflows.yaml` lints workflows with zizmor on every PR - [x] Workflow `name:` and job `name:` contain no spaces (kebab-case) so they can be set as required status checks — verified 2026-09-09 - [ ] `persist-credentials: false` on checkouts that don't push diff --git a/SECURITY.md b/SECURITY.md index 19c8294..743f938 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -26,7 +26,7 @@ hardening checklist; progress is tracked in [DEFENSE_IN_DEPTH.md](./DEFENSE_IN_D - pnpm is pinned via `packageManager` (`pnpm@12.3.0`). - Dependencies install through pnpm with a 7-day cooldown on new versions, lifecycle scripts blocked by default, `trustPolicy: no-downgrade`, and exotic subdependencies blocked. - The lockfile is committed and CI installs with `--frozen-lockfile`. There is no Dependabot config; dependency updates go through reviewed PRs. -- CI workflows default to read-only `contents: read` permissions; generated output is never committed back from CI. +- CI workflows default to read-only `contents: read` permissions; generated output is never committed back from CI; every action is pinned to a full commit SHA. - Workflows do not use `pull_request_target`. - The published package sets `repository.url` to this repo so provenance can map back. - `.github/CODEOWNERS` names `@jaredwray` for `/.github/`, `/.vscode/`, `/.cursor/`, `/.devcontainer/`, and `/scripts/`.