Skip to content

ci: harden CI/CD security#1260

Closed
jpr5 wants to merge 1 commit into
aws:mainfrom
CopilotKit:ci/supply-chain-hardening
Closed

ci: harden CI/CD security#1260
jpr5 wants to merge 1 commit into
aws:mainfrom
CopilotKit:ci/supply-chain-hardening

Conversation

@jpr5

@jpr5 jpr5 commented May 14, 2026

Copy link
Copy Markdown

Summary

  • SHA-pin all GitHub Actions with version comments
  • Add least-privilege permissions blocks to all workflows
  • Fix shell injection (route attacker-controllable values through env)
  • Add persist-credentials: false on read-only checkouts
  • Add zizmor static analysis for workflow security
  • Update Dependabot to daily for github-actions (auto-merge minor/patch)

Part of Phase 2 CI/CD supply chain hardening.

@jpr5 jpr5 requested a review from a team May 14, 2026 21:27
@jpr5

jpr5 commented May 14, 2026

Copy link
Copy Markdown
Author

Opened against wrong repo (fork). Recreating against CopilotKit/agentcore-cli.

@jpr5 jpr5 closed this May 14, 2026
@github-actions github-actions Bot added the size/m PR size: M label May 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/m PR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant