Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ jobs:
bun-version: 1.3.14
# setup-uv stopped publishing floating major tags in v8, so this is pinned
# to an exact release rather than a tracking `@v10`.
- uses: astral-sh/setup-uv@v10.0.1
- uses: astral-sh/setup-uv@v10.2.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security · low
astral-sh/setup-uv is a third-party action referenced by a mutable tag. Pinning to an exact release (instead of a floating @v10) is an improvement, but a tag can still be repointed, so this step can run different code than what was reviewed here. Prefer pinning to the v10.2.0 release commit SHA with the version noted in the adjacent comment. Applies to all four occurrences changed in this PR (two here, two in release.yml).

Suggestion:

Suggested change
- uses: astral-sh/setup-uv@v10.2.0
# setup-uv v10.2.0, pinned to the release commit SHA
- uses: astral-sh/setup-uv@<commit-sha-of-v10.2.0>

with:
# The document tools declare their dependencies with PEP 723 inline
# metadata, so the default lockfile globs match no file and the cache
Expand Down Expand Up @@ -94,7 +94,7 @@ jobs:
bun-version: 1.3.14
# setup-uv stopped publishing floating major tags in v8, so this is pinned
# to an exact release rather than a tracking `@v10`.
- uses: astral-sh/setup-uv@v10.0.1
- uses: astral-sh/setup-uv@v10.2.0
with:
# The document tools declare their dependencies with PEP 723 inline
# metadata, so the default lockfile globs match no file and the cache
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/ocr-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,7 @@ jobs:
- name: Get PR context
id: pr-context
if: github.event_name == 'issue_comment'
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
// issue_comment events have no top-level pull_request fields, so
Expand All @@ -96,7 +96,7 @@ jobs:
core.setOutput('head_sha', pullRequest.head.sha);

- name: Run OpenCodeReview
uses: alibaba/open-code-review@v1.9.9
uses: alibaba/open-code-review@v1.12.10

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security · medium
This third-party action is pinned to a mutable tag rather than a full commit SHA. This workflow runs on pull_request_target (secrets available even for fork PRs) and hands llm_auth_token directly to the action, so if the v1.12.10 tag is ever repointed to malicious code, the LLM API key could be exfiltrated. Pin to the exact commit SHA of the v1.12.10 release and keep the version in a comment, so the executed code is immutable.

Suggestion:

Suggested change
uses: alibaba/open-code-review@v1.12.10
# alibaba/open-code-review v1.12.10, pinned to the release commit SHA
uses: alibaba/open-code-review@<commit-sha-of-v1.12.10>

with:
llm_url: ${{ secrets.OCR_LLM_URL }}
llm_auth_token: ${{ secrets.OCR_LLM_AUTH_TOKEN }}
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ jobs:
bun-version: 1.3.14
# setup-uv stopped publishing floating major tags in v8, so this is pinned
# to an exact release rather than a tracking `@v10`.
- uses: astral-sh/setup-uv@v10.0.1
- uses: astral-sh/setup-uv@v10.2.0
with:
# The document tools declare their dependencies with PEP 723 inline
# metadata, so the default lockfile globs match no file and the cache
Expand Down Expand Up @@ -178,7 +178,7 @@ jobs:
bun-version: 1.3.14
# setup-uv stopped publishing floating major tags in v8, so this is pinned
# to an exact release rather than a tracking `@v10`.
- uses: astral-sh/setup-uv@v10.0.1
- uses: astral-sh/setup-uv@v10.2.0
with:
# The document tools declare their dependencies with PEP 723 inline
# metadata, so the default lockfile globs match no file and the cache
Expand Down
Loading