Skip to content

🔒 ci: clear SonarCloud S8545 and S6506 findings - #146

Merged
konih merged 2 commits into
mainfrom
ci/sonar-hardening
Sep 21, 2026
Merged

konih merged 2 commits into
mainfrom
ci/sonar-hardening

Conversation

@konih

@konih konih commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Two behaviour-preserving hardening fixes from the security sweep.

  • .github/workflows/verify.yaml: the three pinned go install <tool>@<version> steps (Task twice, golangci-lint once) now pass -mod=readonly, so the install cannot rewrite the target module's go.mod/go.sum. Same pinned versions, same binaries (githubactions:S8545).
  • hack/install-git-cliff.sh: the release download uses curl --proto '=https' --tlsv1.2, which also holds across redirects (shell:S6506).

Not changed: go:S4036 in internal/schemadrift/drift.go (exec.Command("git", ...) by bare name). Resolving it means changing how git is located, which is a design choice left to the maintainer.

Local checks: actionlint, shellcheck, hack/lint/workflow_pins_test.sh, install script run against v2.13.1.

go install already resolves a pinned version through the module checksum
database; -mod=readonly additionally forbids the build from rewriting the
target module go.mod/go.sum, so the install is lock-file enforcing.
Clears SonarCloud githubactions:S8545.
curl --proto '=https' --tlsv1.2 also applies to redirects, so a release
asset redirect can no longer downgrade. Clears SonarCloud shell:S6506.
@sonarqubecloud

Copy link
Copy Markdown

@konih
konih merged commit b8123cc into main Sep 21, 2026
7 checks passed
@konih
konih deleted the ci/sonar-hardening branch September 21, 2026 13:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant