Skip to content

Pin shivammathur/setup-php to commit SHA for supply chain safety - #34

Merged
proxymesh merged 1 commit into
mainfrom
cursor/at-rest-security-review-d641
Jul 30, 2026
Merged

Pin shivammathur/setup-php to commit SHA for supply chain safety#34
proxymesh merged 1 commit into
mainfrom
cursor/at-rest-security-review-d641

Conversation

@cursor

@cursor cursor Bot commented Jul 30, 2026

Copy link
Copy Markdown

All other third-party GitHub Actions across the four language workflows are pinned to immutable commit SHAs. The PHP workflow was the only one still referencing a mutable tag (v2), which exposes the CI runner — and the PROXY_URL secret — to a tag-repointing supply chain attack.

This change pins shivammathur/setup-php to its current v2 commit SHA (b604ade2), matching the repository's existing pinning convention used for actions/checkout, actions/setup-python, actions/setup-node, ruby/setup-ruby, and dorny/paths-filter.

Open in Web View Automation 

All other third-party GitHub Actions in the repository workflows are
pinned to immutable commit SHAs.  The PHP workflow was the only one
still referencing a mutable tag (v2), which exposes the CI runner
(and the PROXY_URL secret) to a tag-repointing supply chain attack.

Pin to the current v2 commit SHA (b604ade2) to match the repository's
existing pinning convention.

Co-authored-by: ProxyMesh AI <proxymeshai@users.noreply.github.com>
@proxymesh
proxymesh marked this pull request as ready for review July 30, 2026 15:58

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left a non-blocking comment (not approved by this automation). This PR is not a Dependabot package version bump, so the configured auto-approve criteria do not apply. Owner approval is already present; no additional reviewers were assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: oss dependabot approver

@proxymesh
proxymesh merged commit e51fbb1 into main Jul 30, 2026
10 checks passed
@proxymesh
proxymesh deleted the cursor/at-rest-security-review-d641 branch July 30, 2026 16:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant