GitHub Actions Audit
The daily Actions audit found issues in this repository.
Pinned action integrity
Warnings
arcuru/actions/.github/actions/commit-and-pr@c8144123a is a self-reference running an older copy of .github/actions/commit-and-pr — its content differs from the current tree, so this workflow does not run what is checked in beside it (in .github/workflows/actions-update.yml, .github/workflows/cargo-update.yml, .github/workflows/flake-update.yml)
arcuru/actions/.github/actions/setup-deps-branch@c8144123a is a self-reference running an older copy of .github/actions/setup-deps-branch — its content differs from the current tree, so this workflow does not run what is checked in beside it (in .github/workflows/actions-update.yml, .github/workflows/cargo-update.yml, .github/workflows/flake-update.yml)
arcuru/actions/.github/actions/setup-nix@c8144123a is a self-reference running an older copy of .github/actions/setup-nix — its content differs from the current tree, so this workflow does not run what is checked in beside it (in .github/workflows/actions-update.yml, .github/workflows/cargo-update.yml, .github/workflows/flake-update.yml, .github/workflows/security-audit.yml)
arcuru/actions/.github/actions/verify-pins@fd93c1398 is a self-reference running an older copy of .github/actions/verify-pins — its content differs from the current tree, so this workflow does not run what is checked in beside it (in .github/workflows/actions-audit.yml, .github/workflows/update-hold.yml)
Informational (5) — expected drift on floating tags and branch pins
arcuru/actions/.github/actions/commit-and-pr@c8144123a tracks branch main — on the branch, moves by design (in .github/workflows/actions-update.yml, .github/workflows/cargo-update.yml, .github/workflows/flake-update.yml)
arcuru/actions/.github/actions/scan-pins@6568fce9d tracks branch main — on the branch, moves by design (in .github/workflows/actions-audit.yml, .github/workflows/actions-update.yml, .github/workflows/update-hold.yml)
arcuru/actions/.github/actions/setup-deps-branch@c8144123a tracks branch main — on the branch, moves by design (in .github/workflows/actions-update.yml, .github/workflows/cargo-update.yml, .github/workflows/flake-update.yml)
arcuru/actions/.github/actions/setup-nix@c8144123a tracks branch main — on the branch, moves by design (in .github/workflows/actions-update.yml, .github/workflows/cargo-update.yml, .github/workflows/flake-update.yml, .github/workflows/security-audit.yml)
arcuru/actions/.github/actions/verify-pins@fd93c1398 tracks branch main — on the branch, moves by design (in .github/workflows/actions-audit.yml, .github/workflows/update-hold.yml)
Verified 10 distinct references across 26 uses: lines.
A re-pointed immutable tag is the signature of a force-push supply-chain
attack. The pinned SHA refers to the original commit, so CI does not run
the replacement — but do not bump these actions until the change is
explained upstream.
Workflow security (zizmor)
| Level |
Rule |
Location |
| note |
zizmor/artipacked |
.github/workflows/actions-update.yml:67 |
| note |
zizmor/artipacked |
.github/workflows/cargo-update.yml:60 |
| note |
zizmor/artipacked |
.github/workflows/codeberg-mirror.yml:57 |
| note |
zizmor/artipacked |
.github/workflows/flake-update.yml:61 |
| warning |
zizmor/secrets-inherit |
.github/workflows/self-actions-audit.yml:18 |
| warning |
zizmor/secrets-inherit |
.github/workflows/self-actions-update.yml:26 |
| warning |
zizmor/secrets-inherit |
.github/workflows/self-dependency-hold.yml:16 |
| warning |
zizmor/secrets-inherit |
.github/workflows/self-update-hold.yml:21 |
Last checked: 2026-09-21T06:17:19Z
GitHub Actions Audit
The daily Actions audit found issues in this repository.
Pinned action integrity
Warnings
arcuru/actions/.github/actions/commit-and-pr@c8144123ais a self-reference running an older copy of.github/actions/commit-and-pr— its content differs from the current tree, so this workflow does not run what is checked in beside it (in.github/workflows/actions-update.yml,.github/workflows/cargo-update.yml,.github/workflows/flake-update.yml)arcuru/actions/.github/actions/setup-deps-branch@c8144123ais a self-reference running an older copy of.github/actions/setup-deps-branch— its content differs from the current tree, so this workflow does not run what is checked in beside it (in.github/workflows/actions-update.yml,.github/workflows/cargo-update.yml,.github/workflows/flake-update.yml)arcuru/actions/.github/actions/setup-nix@c8144123ais a self-reference running an older copy of.github/actions/setup-nix— its content differs from the current tree, so this workflow does not run what is checked in beside it (in.github/workflows/actions-update.yml,.github/workflows/cargo-update.yml,.github/workflows/flake-update.yml,.github/workflows/security-audit.yml)arcuru/actions/.github/actions/verify-pins@fd93c1398is a self-reference running an older copy of.github/actions/verify-pins— its content differs from the current tree, so this workflow does not run what is checked in beside it (in.github/workflows/actions-audit.yml,.github/workflows/update-hold.yml)Informational (5) — expected drift on floating tags and branch pins
arcuru/actions/.github/actions/commit-and-pr@c8144123atracks branchmain— on the branch, moves by design (in.github/workflows/actions-update.yml,.github/workflows/cargo-update.yml,.github/workflows/flake-update.yml)arcuru/actions/.github/actions/scan-pins@6568fce9dtracks branchmain— on the branch, moves by design (in.github/workflows/actions-audit.yml,.github/workflows/actions-update.yml,.github/workflows/update-hold.yml)arcuru/actions/.github/actions/setup-deps-branch@c8144123atracks branchmain— on the branch, moves by design (in.github/workflows/actions-update.yml,.github/workflows/cargo-update.yml,.github/workflows/flake-update.yml)arcuru/actions/.github/actions/setup-nix@c8144123atracks branchmain— on the branch, moves by design (in.github/workflows/actions-update.yml,.github/workflows/cargo-update.yml,.github/workflows/flake-update.yml,.github/workflows/security-audit.yml)arcuru/actions/.github/actions/verify-pins@fd93c1398tracks branchmain— on the branch, moves by design (in.github/workflows/actions-audit.yml,.github/workflows/update-hold.yml)Verified 10 distinct references across 26
uses:lines.A re-pointed immutable tag is the signature of a force-push supply-chain
attack. The pinned SHA refers to the original commit, so CI does not run
the replacement — but do not bump these actions until the change is
explained upstream.
Workflow security (zizmor)
Last checked: 2026-09-21T06:17:19Z