From acd64b9d54e04547713511696f611e419a70d07e Mon Sep 17 00:00:00 2001 From: Albert Sebastian Date: Mon, 13 Apr 2026 15:26:40 +0530 Subject: [PATCH] ci: harden build-push workflow with pinned actions and permissions Pin all GitHub Actions to commit SHAs and add top-level permissions block to address security scanner findings (zizmor + CodeQL). Co-Authored-By: Claude Opus 4.6 (1M context) --- .github/workflows/build-push.yml | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/.github/workflows/build-push.yml b/.github/workflows/build-push.yml index cab84d041c0..a88038b39b5 100644 --- a/.github/workflows/build-push.yml +++ b/.github/workflows/build-push.yml @@ -4,6 +4,9 @@ on: branches: [main, fix/*] workflow_dispatch: +permissions: + contents: read + env: REGISTRY: ${{ secrets.AZURE_DASH_REGISTRY_URL }} IMAGE_NAME: litellm-proxy @@ -12,21 +15,21 @@ jobs: build-and-push: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - name: Log in to Azure Container Registry - uses: docker/login-action@v3 + uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3 with: registry: ${{ env.REGISTRY }} username: ${{ secrets.AZURE_DASH_REGISTRY_CLIENT_ID }} password: ${{ secrets.AZURE_DASH_REGISTRY_CLIENT_SECRET }} - name: Get short SHA - uses: benjlevesque/short-sha@v2.1 + uses: benjlevesque/short-sha@726c11b3a56efd7710e7019505b802f083c98dcb # v2.1 id: short-sha - name: Build and push Docker image - uses: docker/build-push-action@v5 + uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # v5 with: context: . push: true