CI/CD supply-chain & credential hardening — code-navigator
Part of the org-wide shaharia-lab CI/CD supply-chain security initiative (credentials first → pinning → provenance). Tracked centrally in the .github epic.
Severity: Medium 🟡
Repo-specific actions
Baseline hardening
Reference
Full per-repo plan & rationale: https://app.vibexp.io/artifacts/017f21c2-f378-435f-80e1-b0524459051b/shaharia-lab-cicd-security-remediation-plan
CI/CD supply-chain & credential hardening — code-navigator
Part of the org-wide shaharia-lab CI/CD supply-chain security initiative (credentials first → pinning → provenance). Tracked centrally in the
.githubepic.Severity: Medium 🟡
Repo-specific actions
Cargo.lockand build with--lockedsoftprops/action-gh-releaseanddtolnay/rust-toolchain@stable)permissions: contents: readto ci.yml; scopeHOMEBREW_TAP_TOKEN; push formula via PR notgh api PUTto mainBaseline hardening
github-actions(no auto-merge)permissions: { contents: read }@sha256:); deploy immutable${{ github.sha }}, never:latestReference
Full per-repo plan & rationale: https://app.vibexp.io/artifacts/017f21c2-f378-435f-80e1-b0524459051b/shaharia-lab-cicd-security-remediation-plan