SonarCloud flags the CI supply chain (rules S7637 / S6505 / S8543). Triaged as accepted for now and deferred so the security-triage change stays focused.
Scope
- S7637 — third-party
uses: entries are pinned to mutable tags instead of commit SHAs (gitleaks, docker/*, aquasecurity/trivy-action, appleboy/ssh-action).
- S6505 / S8543 —
npm ci / npx steps run lifecycle scripts and npx is not explicitly restricted to the lockfile-pinned local install.
Proposal
- Pin each third-party action to its commit SHA with a
# vX.Y.Z comment so Dependabot keeps updating it.
- Use
npx --no-install (or the local node_modules/.bin binary) instead of bare npx where no install is intended.
- Keep lifecycle scripts enabled where the build requires them (Angular/esbuild postinstall); document the exceptions.
Related: T2 security triage.
SonarCloud flags the CI supply chain (rules S7637 / S6505 / S8543). Triaged as accepted for now and deferred so the security-triage change stays focused.
Scope
uses:entries are pinned to mutable tags instead of commit SHAs (gitleaks, docker/*, aquasecurity/trivy-action, appleboy/ssh-action).npm ci/npxsteps run lifecycle scripts andnpxis not explicitly restricted to the lockfile-pinned local install.Proposal
# vX.Y.Zcomment so Dependabot keeps updating it.npx --no-install(or the localnode_modules/.binbinary) instead of barenpxwhere no install is intended.Related: T2 security triage.