From 193d5af639eef3a7670682982f49b05dd5e8e8f2 Mon Sep 17 00:00:00 2001 From: Benoit Tigeot Date: Wed, 29 Jul 2026 17:20:35 +0200 Subject: [PATCH 1/5] ci: enforce 7-day cooldown on dependabot updates Give a week for new dependency releases to be vetted before Dependabot opens PRs, reducing exposure to freshly published malicious versions. Signed-off-by: Benoit Tigeot --- .github/dependabot.yml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 1b1de9e55..b795dde19 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -17,6 +17,8 @@ updates: - "k8s.io/cli-runtime" - "k8s.io/client-go" - "k8s.io/kubectl" + cooldown: + default-days: 7 - package-ecosystem: "gomod" target-branch: "main" directory: "/" @@ -32,6 +34,8 @@ updates: - "k8s.io/cli-runtime" - "k8s.io/client-go" - "k8s.io/kubectl" + cooldown: + default-days: 7 - package-ecosystem: "github-actions" target-branch: "main" directory: "/" @@ -41,6 +45,8 @@ updates: github-actions: patterns: - "*" + cooldown: + default-days: 7 - # Keep dev-v3 GitHub Actions up to date, while Helm v3 is within support package-ecosystem: "github-actions" target-branch: "dev-v3" @@ -51,3 +57,5 @@ updates: github-actions: patterns: - "*" + cooldown: + default-days: 7 From 070fd6056dfd8673e591606b4a7639916a412c7c Mon Sep 17 00:00:00 2001 From: Benoit Tigeot Date: Wed, 29 Jul 2026 17:20:54 +0200 Subject: [PATCH 2/5] ci: stop persisting checkout credentials in workflows Set `persist-credentials: false` on every `actions/checkout` so the auto-injected token is not left in `.git/config`, where a later step or uploaded artifact could leak it. Signed-off-by: Benoit Tigeot --- .github/workflows/build-test.yml | 2 ++ .github/workflows/codeql-analysis.yml | 2 ++ .github/workflows/golangci-lint.yml | 2 ++ .github/workflows/release.yml | 2 ++ 4 files changed, 8 insertions(+) diff --git a/.github/workflows/build-test.yml b/.github/workflows/build-test.yml index 9503674ed..bdd3cc5b8 100644 --- a/.github/workflows/build-test.yml +++ b/.github/workflows/build-test.yml @@ -19,6 +19,8 @@ jobs: steps: - name: Checkout source code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # pin@v7.0.1 + with: + persist-credentials: false - name: Add variables to environment file run: cat ".github/env" >> "$GITHUB_ENV" - name: Setup Go diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index d8c1a9d12..b978bca88 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -45,6 +45,8 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # pin@v7.0.1 + with: + persist-credentials: false # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL diff --git a/.github/workflows/golangci-lint.yml b/.github/workflows/golangci-lint.yml index 955f12002..2a359568d 100644 --- a/.github/workflows/golangci-lint.yml +++ b/.github/workflows/golangci-lint.yml @@ -14,6 +14,8 @@ jobs: steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # pin@v7.0.1 + with: + persist-credentials: false - name: Add variables to environment file run: cat ".github/env" >> "$GITHUB_ENV" - name: Setup Go diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2b2f93f4d..af265a689 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -23,6 +23,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # pin@v7.0.1 with: fetch-depth: 0 + persist-credentials: false - name: Add variables to environment file run: cat ".github/env" >> "$GITHUB_ENV" @@ -88,6 +89,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # pin@v7.0.1 with: fetch-depth: 0 + persist-credentials: false - name: Add variables to environment file run: cat ".github/env" >> "$GITHUB_ENV" From 4c5c9ead246076c4f510c057c22898ff1ab79a9f Mon Sep 17 00:00:00 2001 From: Benoit Tigeot Date: Wed, 29 Jul 2026 17:21:03 +0200 Subject: [PATCH 3/5] ci: disable setup-go cache to prevent cache poisoning The build-test workflow runs on push/PR to protected branches; leaving `actions/setup-go` caching on lets a PR-populated cache be restored into a trusted run. Disable it. Signed-off-by: Benoit Tigeot --- .github/workflows/build-test.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/build-test.yml b/.github/workflows/build-test.yml index bdd3cc5b8..136754568 100644 --- a/.github/workflows/build-test.yml +++ b/.github/workflows/build-test.yml @@ -28,6 +28,7 @@ jobs: with: go-version: '${{ env.GOLANG_VERSION }}' check-latest: true + cache: false - name: Test source headers are present run: make test-source-headers - name: Check if go modules need to be tidied From 8fae8dd4c0936f78dec4f5b9da0f6d8d8ccd754c Mon Sep 17 00:00:00 2001 From: Benoit Tigeot Date: Wed, 29 Jul 2026 17:21:07 +0200 Subject: [PATCH 4/5] ci: pass ref name via env to block template injection Interpolating `github.ref_name` directly into the release `run` block lets an attacker-controlled ref name execute shell code. Pass it through the `GITHUB_REF_NAME` env var instead. Signed-off-by: Benoit Tigeot --- .github/workflows/release.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index af265a689..8f0a3429e 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -39,8 +39,8 @@ jobs: run: | set -eu -o pipefail - make build-cross VERSION="${{ github.ref_name }}" - make dist checksum VERSION="${{ github.ref_name }}" + make build-cross VERSION="${GITHUB_REF_NAME}" + make dist checksum VERSION="${GITHUB_REF_NAME}" - name: Set latest version run: | From fe7ad77aa1e1559c72e30c3cdc08b7eb0f27d4c6 Mon Sep 17 00:00:00 2001 From: Benoit Tigeot Date: Wed, 29 Jul 2026 17:24:24 +0200 Subject: [PATCH 5/5] ci: scope release workflow token to contents read `read-all` grants far more than the release jobs use; they only need repo read for checkout and authenticate uploads via Azure secrets. Narrow `GITHUB_TOKEN` to `contents: read`. Signed-off-by: Benoit Tigeot --- .github/workflows/release.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8f0a3429e..87b8caaa0 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -7,7 +7,8 @@ on: branches: - main -permissions: read-all +permissions: + contents: read # Note the only differences between release and canary-release jobs are: # - only canary passes --overwrite flag