Skip to content

GitHub Actions Audit #6

Description

@github-actions

GitHub Actions Audit

The daily Actions audit found issues in this repository.

Pinned action integrity

Warnings

  • arcuru/actions/.github/actions/commit-and-pr@c8144123a is a self-reference running an older copy of .github/actions/commit-and-pr — its content differs from the current tree, so this workflow does not run what is checked in beside it (in .github/workflows/actions-update.yml, .github/workflows/cargo-update.yml, .github/workflows/flake-update.yml)
  • arcuru/actions/.github/actions/setup-deps-branch@c8144123a is a self-reference running an older copy of .github/actions/setup-deps-branch — its content differs from the current tree, so this workflow does not run what is checked in beside it (in .github/workflows/actions-update.yml, .github/workflows/cargo-update.yml, .github/workflows/flake-update.yml)
  • arcuru/actions/.github/actions/setup-nix@c8144123a is a self-reference running an older copy of .github/actions/setup-nix — its content differs from the current tree, so this workflow does not run what is checked in beside it (in .github/workflows/actions-update.yml, .github/workflows/cargo-update.yml, .github/workflows/flake-update.yml, .github/workflows/security-audit.yml)
  • arcuru/actions/.github/actions/verify-pins@fd93c1398 is a self-reference running an older copy of .github/actions/verify-pins — its content differs from the current tree, so this workflow does not run what is checked in beside it (in .github/workflows/actions-audit.yml, .github/workflows/update-hold.yml)
Informational (5) — expected drift on floating tags and branch pins
  • arcuru/actions/.github/actions/commit-and-pr@c8144123a tracks branch main — on the branch, moves by design (in .github/workflows/actions-update.yml, .github/workflows/cargo-update.yml, .github/workflows/flake-update.yml)
  • arcuru/actions/.github/actions/scan-pins@6568fce9d tracks branch main — on the branch, moves by design (in .github/workflows/actions-audit.yml, .github/workflows/actions-update.yml, .github/workflows/update-hold.yml)
  • arcuru/actions/.github/actions/setup-deps-branch@c8144123a tracks branch main — on the branch, moves by design (in .github/workflows/actions-update.yml, .github/workflows/cargo-update.yml, .github/workflows/flake-update.yml)
  • arcuru/actions/.github/actions/setup-nix@c8144123a tracks branch main — on the branch, moves by design (in .github/workflows/actions-update.yml, .github/workflows/cargo-update.yml, .github/workflows/flake-update.yml, .github/workflows/security-audit.yml)
  • arcuru/actions/.github/actions/verify-pins@fd93c1398 tracks branch main — on the branch, moves by design (in .github/workflows/actions-audit.yml, .github/workflows/update-hold.yml)

Verified 10 distinct references across 26 uses: lines.

A re-pointed immutable tag is the signature of a force-push supply-chain
attack.
The pinned SHA refers to the original commit, so CI does not run
the replacement — but do not bump these actions until the change is
explained upstream.

Workflow security (zizmor)

Level Rule Location
note zizmor/artipacked .github/workflows/actions-update.yml:67
note zizmor/artipacked .github/workflows/cargo-update.yml:60
note zizmor/artipacked .github/workflows/codeberg-mirror.yml:57
note zizmor/artipacked .github/workflows/flake-update.yml:61
warning zizmor/secrets-inherit .github/workflows/self-actions-audit.yml:18
warning zizmor/secrets-inherit .github/workflows/self-actions-update.yml:26
warning zizmor/secrets-inherit .github/workflows/self-dependency-hold.yml:16
warning zizmor/secrets-inherit .github/workflows/self-update-hold.yml:21

Last checked: 2026-09-21T06:17:19Z

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions