Skip to content

ci: enhance backport workflow security (backport #1977)#1982

Open
mergify[bot] wants to merge 1 commit intorelease/v4.3.xfrom
mergify/bp/release/v4.3.x/pr-1977
Open

ci: enhance backport workflow security (backport #1977)#1982
mergify[bot] wants to merge 1 commit intorelease/v4.3.xfrom
mergify/bp/release/v4.3.x/pr-1977

Conversation

@mergify
Copy link
Contributor

@mergify mergify bot commented Mar 16, 2026

Pinned action to commit SHA — tibdex/backport@9565281 # v2. A compromised or force-pushed v2 tag can no longer substitute malicious code; the runner will only execute the exact commit that was audited.

Restricted permissions — added an explicit block with only contents: write (to push the backport branch) and pull-requests: write (to open the PR and post comments). All other permissions (actions, id-token, packages, etc.) default to none, limiting blast radius if the action is ever abused.


This is an automatic backport of pull request #1977 done by Mergify.

Pinned action to commit SHA —
tibdex/backport@9565281 # v2. A
compromised or force-pushed v2 tag can no longer substitute malicious
code; the runner will only execute the exact commit that was audited.

Restricted permissions — added an explicit block with only contents:
write (to push the backport branch) and pull-requests: write (to open
the PR and post comments). All other permissions (actions, id-token,
packages, etc.) default to none, limiting blast radius if the action is
ever abused.

(cherry picked from commit 65d793a)
@mergify mergify bot requested a review from a team as a code owner March 16, 2026 20:41
@mergify mergify bot requested review from KonradStaniec and RafilxTenfen March 16, 2026 20:41
@github-actions
Copy link
Contributor

🔐 Commit Signature Verification

One or more commits failed verification

Commit Author Signature Key Type Key Check
1184e5838510 liam-icheng-lai -

Summary

  • Commits verified: 1
  • Result: ❌ Failures detected (see table above)

Required key type: sk-ssh-ed25519 (FIDO2 hardware key)

Last verified: 2026-03-16 20:41 UTC

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant