From ee977a8610d982090af842bc44aa9aa0cba129ed Mon Sep 17 00:00:00 2001 From: Markus Pesch Date: Thu, 10 Sep 2026 21:40:31 +0200 Subject: [PATCH] fix(ci): pin actions to their commit sha Floating tags let a compromised or force pushed release change what the workflows execute. Pinning the actions to a commit sha and restricting the default token to read access limits the blast radius of a supply chain attack. The outdated ansible-lint and markdownlint-cli2 versions are raised along with the pinning. The ansible-lint run installs the collections of the molecule scenario, because the scenario is linted as well and depends on community.docker beside the community.general requirement of the role. Co-authored-by: Copilot --- .gitea/workflows/ansible-linters.yaml | 5 +++++ .gitea/workflows/markdown-linters.yaml | 3 +++ .gitea/workflows/release.yaml | 3 +++ 3 files changed, 11 insertions(+) diff --git a/.gitea/workflows/ansible-linters.yaml b/.gitea/workflows/ansible-linters.yaml index 0b81b76..b81e47b 100644 --- a/.gitea/workflows/ansible-linters.yaml +++ b/.gitea/workflows/ansible-linters.yaml @@ -7,6 +7,9 @@ on: branches: [ '**' ] tags-ignore: [ '**' ] +permissions: + contents: read + jobs: ansible-lint: runs-on: @@ -17,4 +20,6 @@ jobs: uses: ansible/ansible-lint@665d9e07a1943254d2910faffc106adaf7ea7294 # v26.8.0 with: args: "--config-file .ansible-lint" + # The molecule scenario is linted as well, so its collections are required beside the ones of the role. + requirements_file: "molecule/default/collections.yml" setup_python: "true" diff --git a/.gitea/workflows/markdown-linters.yaml b/.gitea/workflows/markdown-linters.yaml index c98e609..b35a8eb 100644 --- a/.gitea/workflows/markdown-linters.yaml +++ b/.gitea/workflows/markdown-linters.yaml @@ -7,6 +7,9 @@ on: branches: [ '**' ] tags-ignore: [ '**' ] +permissions: + contents: read + jobs: markdown-lint: runs-on: diff --git a/.gitea/workflows/release.yaml b/.gitea/workflows/release.yaml index f4dc263..25cd0a5 100644 --- a/.gitea/workflows/release.yaml +++ b/.gitea/workflows/release.yaml @@ -6,6 +6,9 @@ on: - '**' workflow_dispatch: {} +permissions: + contents: read + jobs: release: name: Release Ansible Role