Skip to content

chore(ci): protect package installs with Aegis - #900

Draft
decofe wants to merge 6 commits into
wevm:mainfrom
decofe:centaur/aegis-ci-1789559001
Draft

decofe wants to merge 6 commits into
wevm:mainfrom
decofe:centaur/aegis-ci-1789559001

Conversation

@decofe

@decofe decofe commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

Add pinned Aegis/runner protection before installs in verification, prerelease, publishing, audit-remediation, and friction-log jobs, with job-scoped OIDC. Make shared pnpm installs explicitly frozen while preserving package versions and release behavior. External conformance workflows, container downloads, and cached/prebuilt artifacts remain outside host-package coverage.

Add the shared GitHub Actions scanner, pinned to b35994a2, on pull requests, default-branch pushes, and manual runs. Enable zizmor, actionlint, and action-pin verification; keep the secure-runner presence check advisory.

Pin workflow actions with verifiable release comments and fix the syntax/security findings exposed by the scanner. Pin external conformance workflows to a commit. Scope pinact exceptions to four exact workflow paths and SHAs from mpp-tools and wevm/actions, which publish no tags. These exceptions skip pinact verification, including release-age checks, and must be reassessed on pin updates.

AI-assisted changes.

Prompted by: @grandizzy

Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
@pkg-pr-new

pkg-pr-new Bot commented Sep 16, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/mppx@900

commit: c7b0c32

grandizzy and others added 5 commits September 23, 2026 07:31
Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants