root - chore: defense - wrap installs with Socket Firewall - #70
Conversation
Install SHA-pinned SocketDev/action after checkout on every job and run sfw pnpm install --frozen-lockfile. Reconcile Actions SHA pins as merged in PR #69. Co-authored-by: Jared Wray <me@jaredwray.com>
Co-authored-by: Jared Wray <me@jaredwray.com>
There was a problem hiding this comment.
Code Review
This pull request updates the security documentation in DEFENSE_IN_DEPTH.md and SECURITY.md to reflect that GitHub Actions are now pinned to full commit SHAs. The reviewer suggested marking the Socket Firewall integration checklist item as completed rather than pending, since this pull request implements that integration.
| - [ ] Every action pinned to a full commit SHA (`npx actions-up`) (PR #69 pending) | ||
| - [ ] Every job installs Socket Firewall (`SocketDev/action` SHA-pinned, `firewall-version` pinned); `pnpm install` / `npm install` run as `sfw pnpm install` / `sfw npm install` | ||
| - [x] Every action pinned to a full commit SHA (`npx actions-up`) — PR #69 | ||
| - [ ] Every job installs Socket Firewall (`SocketDev/action` SHA-pinned, `firewall-version` pinned); `pnpm install` / `npm install` run as `sfw pnpm install` / `sfw npm install` (PR #70 pending) |
There was a problem hiding this comment.
Since this pull request implements the Socket Firewall integration (as described in the PR title and summary), this checklist item should be marked as completed ([x]) and the (PR pending) suffix should be removed.
| - [ ] Every job installs Socket Firewall (`SocketDev/action` SHA-pinned, `firewall-version` pinned); `pnpm install` / `npm install` run as `sfw pnpm install` / `sfw npm install` (PR #70 pending) | |
| - [x] Every job installs Socket Firewall (`SocketDev/action` SHA-pinned, `firewall-version` pinned); `pnpm install` / `npm install` run as `sfw pnpm install` / `sfw npm install` |
There was a problem hiding this comment.
Leaving this unchecked with (PR #70 pending) on purpose. security-status-tracking only flips an item to - [x] … — PR #n after that PR merges. Checking it off here would claim Socket Firewall is on main before it is.
|
Gemini suggested checking off the Socket Firewall item in this PR. I left it as |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #70 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 3 3
Lines 19 19
Branches 1 1
=========================================
Hits 19 19 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
* ci: lint GitHub Actions workflows with zizmor Add check-workflows.yaml so every PR runs zizmor with Socket Firewall in front. Reconcile Socket Firewall as merged in PR #70. Co-authored-by: Jared Wray <me@jaredwray.com> * chore: record PR #71 on the zizmor checklist item Co-authored-by: Jared Wray <me@jaredwray.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Please check if the PR fulfills these requirements
What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)
CI / supply-chain hardening.
Summary
Installs Socket Firewall Free on every job and wraps
pnpm installwithsfw(defense-in-depth § 4).Status update
DEFENSE_IN_DEPTH.md: Socket Firewall → (PR #70 pending); Actions SHA pins → PR #69Changes
SocketDev/action(mode: firewall-free,firewall-version: 1.15.1) immediately after checkout ontests,release, andcode-coveragesfw pnpm install --frozen-lockfileinstead of barepnpm installVerification
steps:has the Firewall steppnpm install/npm installin workflowsnpx actions-up -y --style shareports SocketDev/action up to datetests(build-test22/24/26),code-coverage(build), CodeQLReference
defense-in-depth-nodejs § 4