Skip to content

Conversation

@sayo-ep
Copy link
Contributor

@sayo-ep sayo-ep commented Oct 30, 2025

This PR pins the AButler/upload-release-assets action from @v3.0 to the explicit version @v3.0.1 following a security review. Pinning to exact versions is a best practice that enables:

  • Version Control: Explicit tracking of which version is in use
  • Change Management: Controlled updates with review before adopting new versions
  • Security Monitoring: Easier tracking of security advisories
  • Reproducibility: Consistent behavior across workflow runs

Security Review Summary

Key Findings:

  • OSSF Scorecard: 4.8/10
  • Code Quality: Secure (0 SAST findings)
  • Known Issues: 12 CVEs in transitive dependencies (ReDoS vulnerabilities with LOW exploitability in CI/CD)
  • Maintenance: Active (5+ years, latest release March 2025)
  • Risk Level: MEDIUM (dependency CVEs only)

Why Continue Using This Action:

  • Simple, declarative syntax with native glob support
  • Clean security profile (0 code vulnerabilities)
  • CVEs have low practical risk in sandboxed GitHub Actions environment
  • Well-maintained with consistent updates

Pin AButler/upload-release-assets from @v3.0 to @v3.0.1 for explicit version control and improved security monitoring.
@sayo-ep sayo-ep requested review from a team as code owners October 30, 2025 17:06
@Justintime50 Justintime50 merged commit 8f169f5 into main Nov 3, 2025
22 checks passed
@Justintime50 Justintime50 deleted the abutler-upload-release-assets-review branch November 3, 2025 16:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants