.github/workflows/scan-and-report.yml installs the scanner with
cargo install --git https://github.com/hyperpolymath/panic-attack --branch main
A caller that pins the reusable workflow by SHA, for example echidna at @5ee2565…, still runs whatever binary main holds at run time. A push to main can therefore change every caller's scan results without changing any caller's pin (CWE-829). CodeRabbit raised this on hyperpolymath/echidna#399 (r4154702680). It is pre-existing: the earlier pin 27b3d93 has the same line.
Acceptance criteria
.github/workflows/scan-and-report.ymlinstalls the scanner withA caller that pins the reusable workflow by SHA, for example
echidnaat@5ee2565…, still runs whatever binarymainholds at run time. A push tomaincan therefore change every caller's scan results without changing any caller's pin (CWE-829). CodeRabbit raised this on hyperpolymath/echidna#399 (r4154702680). It is pre-existing: the earlier pin27b3d93has the same line.Acceptance criteria
--rev <40-hex sha>), not--branch main.--revto the commit that contains it, or it takes an input defaulting to a SHA kept in step by the release process. The chosen mechanism is documented in the workflow header.bash -nplus grep test, fails if--branchor a tag reappears in the install line.gh search code "scan-and-report.yml@"and then verified by enumeration) are bumped to the fixed SHA.