Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
name: CI

on:
pull_request:
push:
branches:
- main

permissions:
contents: read

concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
verify:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v6

- name: Set up Bun
uses: oven-sh/setup-bun@v2
Comment on lines +21 to +24

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -eu
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/ci.yml
printf '%s\n' '--- action references ---'
rg -n 'uses:' .github/workflows
printf '%s\n' '--- repository pinning guidance ---'
rg -n -i 'pin|commit sha|checkout@|setup-bun@|dependabot' .github README.md .github 2>/dev/null || true
printf '%s\n' '--- remote tag metadata ---'
if command -v gh >/dev/null 2>&1; then
  for spec in 'actions/checkout:v6' 'oven-sh/setup-bun:v2'; do
    repo=${spec%:*}
    tag=${spec#*:}
    printf '%s\n' "$spec"
    gh api "repos/$repo/git/ref/tags/$tag" --jq '{object_sha:.object.sha,object_type:.object.type}' || true
  done
else
  printf '%s\n' 'gh is unavailable'
fi

Repository: nino-ts/http

Length of output: 2141


Pin action references to full commit SHAs.

actions/checkout@v6 and oven-sh/setup-bun@v2 use mutable tags. Pin both actions to full commit SHAs to prevent tag movement from changing executed code.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml around lines 21 - 24, Update the actions/checkout
and oven-sh/setup-bun references in the CI workflow to immutable full commit
SHAs instead of the mutable v6 and v2 tags, preserving their existing action
versions and configuration.

with:
bun-version: latest

- name: Install dependencies
run: bun install --frozen-lockfile

- name: Test
run: bun test

- name: Lint
run: bun run lint