Conversation
added 2 commits
September 27, 2026 04:40
Owner's draft from the phase-zero-trust working tree, committed as written so the follow-up fix is reviewable against it.
The draft release workflow built identically named binaries, SHA256SUMS and SBOMs on three runners and merged them into one directory, so the release would have carried one unlabeled binary of unknown OS and a checksum file that did not match the attachments. It also ran with a workflow-wide contents:write token and mutable action tags, including two third-party actions. This version: - verifies the tag equals VERSION and `across version` before building - runs the test suite, then builds and packages one archive per tested target (across_<version>_<goos>_<goarch>.tar.gz for linux/amd64 and darwin/arm64); Windows is compile-only in CI and is not released - computes a single SHA256SUMS in the publish job over the archives, the module inventory and one SPDX SBOM, and attests build provenance for exactly those subjects - scopes contents:write/id-token/attestations to the publish job, pins every action to a commit SHA, pins syft, disables the SBOM action's own uploads, and checks out without persisted credentials - creates a draft pre-release so a maintainer reviews it before publishing
This was referenced Sep 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds the tag-triggered release workflow from the
chore/phase-zero-trustworking tree, held back into its own PR as the audit recommended. Two commits: the owner's draft exactly as written, then the fix, so the change is reviewable against the draft.The draft built identically named outputs on three runners (
dist/across,dist/across-agent-*,dist/SHA256SUMS,dist/go-modules.json,dist/sbom.spdx.json) and merged them withmerge-multiple: trueinto onedist/, so the release would have carried one unlabeled binary of unknown OS and aSHA256SUMSthat did not match the attachments. It also ran with a workflow-widecontents: writetoken and tag-pinned actions (two third-party), installed an unused Node toolchain, and relied onsha256sumon macOS.The fixed workflow:
VERSIONandacross versionbefore building;across_<version>_linux_amd64.tar.gz(ubuntu-latest) andacross_<version>_darwin_arm64.tar.gz(macos-latest), each containingacross, the nineacross-agent-*binaries, LICENSE, README and CHANGELOG. Windows is compile-only in CI and is not released;SHA256SUMSin the publish job over the archives, the module inventory and a single SPDX SBOM, and attests build provenance for exactly those subjects (actions/attest-build-provenance);contents: write,id-token: writeandattestations: writeto the publish job only; pins every action to a commit SHA; pins syft; disables the SBOM action's own artifact/release uploads; checks out without persisted credentials; disables build cache for release builds;Findings addressed
permissions: contents: writeat workflow level,actions/checkout@v4,actions/setup-go@v5,actions/setup-node@v4,anchore/sbom-action@v0,actions/upload-artifact@v4,actions/download-artifact@v4,softprops/action-gh-release@v2, no signature/attestation) — SHA pins, job-scoped write permissions, provenance attestation overSHA256SUMS.Not reproduced / deferred
Verification
actionlint .github/workflows/release.yml(v1.7.12)ls-count warning was fixed with a bash array)GITHUB_REF_NAME=v0.0.1version ok: 0.0.1 / 0.0.1;v9.9.9detected as a mismatchacross_0.0.1_darwin_arm64.tar.gzcontainingacross, the nineacross-agent-*binaries, LICENSE, README.md, CHANGELOG.mdgh api repos/<action>/git/ref/tags/<tag>(annotatedanchore/sbom-actiontag dereferenced to its commit)Follow-ups
v0.0.2-rc.1after VERSION is bumped) to exercise the workflow end to end, then decide whether to keep drafts.🤖 Generated with Claude Code