Auditor
Base images are pinned by digest, CI actions are pinned by commit, and the CI declared the hash of the artifact it built.
1.0.3: the artifact hash is an input of the RUN, not a property of the checkout: a run that declares none (a manual run launched from the app) is not-applicable with the reason "artifact hash not provided by this run mode" and no findings, never a FAIL; with an artifact declared the rule is unchanged. (1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative.))
| if (!artifact.sha256 && !artifact.imageDigest && !artifact.codeSha256) return { status: 'not-applicable', summary: 'not applicable: artifact hash not provided by this run mode', findings: [] }; |
| const m = /^s*FROMs+([^s]+)/i.exec(line); |
| if (m && !/@sha256:[0-9a-f]{64}/.test(m[1])) findings.push({ severity: 'high', path, line: i + 1, message: `base image ${m[1]} is not pinned by digest` }); |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.