@main that silently changes underneath a project (the 2024 tj-actions/changed-files incident).swift (SwiftPM) and github-actions, weekly.
uses: line in ci.yml and pages.yml moved from a mutable tag (@v4) to the tag's resolved commit SHA with the version kept as a trailing # v4 comment, which Dependabot understands and keeps updated. Resolving a SHA takes two API hops, because a tag ref can point at an annotated tag object rather than the commit itself. One honest mistake worth recording: my first commit staged .github/ wholesale and swept 41 vale-sync style files into the PR; a follow-up commit dropped them and the diff settled at exactly 3 files.
$ gh api repos/actions/checkout/git/ref/tags/v4 # -> object sha (may be a tag object) $ gh api repos/actions/checkout/git/tags/<sha> # -> the actual commit actions/checkout@v4 11d5960a326750d5838078e36cf38b85af677262 actions/cache@v4 0057852bfaa89a56745cba8c7296529d2fc39830 actions/deploy-pages@v4 d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e
.github/dependabot.yml covers swift and github-actions. ✓uses: lines across both workflows pinned by commit SHA. ✓Verified OK.
release.yml: on any v* tag it builds the release binary, zips it, signs it with cosign keylessly (the job's OIDC token becomes a short-lived Fulcio certificate, logged in Rekor), and attaches the artifact plus its .cosign.bundle to the GitHub release. The README now documents the exact verify-blob command, pinned to this repo's release.yml identity. Exercising the mechanics locally against the existing v1.1 DMG with a throwaway key caught a real bug before it shipped: cosign v3 removed --output-signature/--output-certificate and requires --bundle, so the workflow as first written would have failed on its very first tag. The local demo also proved the point of the exercise: the intact DMG verifies OK, and the same DMG with one byte flipped is rejected.
$ cosign sign-blob --key cosign.key --yes --bundle MacDirStat-1.1.dmg.cosign.bundle MacDirStat-1.1.dmg Wrote bundle to file MacDirStat-1.1.dmg.cosign.bundle $ cosign verify-blob --key cosign.pub --bundle ... MacDirStat-1.1.dmg Verified OK $ cosign verify-blob --key cosign.pub --bundle ... tampered.dmg # one byte flipped Error: failed to verify signature
v1.2.0 tagged; workflow built, signed, and published the release. Verified from a clean download with the README command: Verified OK. ✓js-yaml 4.1.1, published two days before the scan. It is a quadratic-CPU parsing bug: a YAML document chaining merge keys (<<: *anchor) forces O(N²) work for O(N) input, so a sub-100KB document can hang the parser for seconds. The interesting part is who is affected: npm ls shows js-yaml reaches this repo only through eslint and the shadcn CLI, both dev-time tools, and the site is a static export that parses no YAML at runtime. High severity, near-zero exposure here; that judgment is the whole point. I fixed what was fixable anyway: npm update bumped js-yaml to 4.3.0 plus five other flagged packages, and the re-scan dropped from 16 findings to 1. The leftover is postcss 8.4.31, which Next.js itself pins: Medium, build-time only, tracked rather than fought.
$ syft . -o cyclonedx-json=sbom.json # 482 components $ grype sbom:sbom.json js-yaml 4.1.1 4.3.0 GHSA-52cp-r559-cp3m High brace-expansion 5.0.6 5.0.7 GHSA-3jxr-9vmj-r5cp High ... 14 more (hono, qs, postcss, body-parser, @babel/core) $ npm ls js-yaml # eslint + shadcn -> js-yaml (dev-time only) $ npm update js-yaml brace-expansion hono qs body-parser @babel/core $ grype sbom:sbom-after.json postcss 8.4.31 8.5.10 GHSA-qx2v-qp2m-jg93 Medium # pinned by Next itself
sbom.json generated for a real project. ✓ (482 components)permissions block, so every job got a default token with write access to repo contents; build-and-test needs read-only) and Security-Policy (no SECURITY.md, so the only way to report a vulnerability was a public issue). Two more zeros, Dependency-Update-Tool and Pinned-Dependencies, are already covered by the Dependabot PR #12 from task 1, so the two PRs together should move four checks off zero once merged.
$ export GITHUB_AUTH_TOKEN=$(gh auth token) $ scorecard --repo=github.com/Ti-03/MacDirStat AGGREGATE: 3.0 / 10 0 Token-Permissions default token can write contents 0 Security-Policy no SECURITY.md 0 Dependency-Update-Tool (fixed by PR #12) 0 Pinned-Dependencies (fixed by PR #12) 0 Branch-Protection, Code-Review, Fuzzing, ... settings/process 10 License, CI-Tests, Dangerous-Workflow, Binary-Artifacts, Vulnerabilities
npm ls showing it only enters via eslint and shadcn at dev time in a static-export site. Severity is not exposure. Fixed with a one-line update anyway.