Skip to content

chore: use grok-build-0.1 for SquidGate - #1

Merged
DotNetRussell merged 2 commits into
masterfrom
chore/squidgate-grok-build-0.1
Aug 1, 2026
Merged

DotNetRussell merged 2 commits into
masterfrom
chore/squidgate-grok-build-0.1

Conversation

@DotNetRussell

Copy link
Copy Markdown
Collaborator

Point SquidGate at xAI grok-build-0.1 (custom provider, api.x.ai). Uses LLM_API_KEY repo secret.

@github-actions

github-actions Bot commented Aug 1, 2026

Copy link
Copy Markdown

🛡️ Security Scan Results

The changes add a GitHub workflow using an unpinned third-party action, creating a supply chain security risk for the passed LLM secret and granted permissions.

MEDIUM — Unpinned third-party GitHub Action

File: .github/workflows/squidgate.yml:21 | Confidence: high | Category: supply_chain

The workflow references the external action 'SquidSec/SquidGate@v1' using a mutable version tag instead of a specific commit SHA. This introduces supply chain risk because the tag can be moved to point to malicious code, potentially exfiltrating the LLM_API_KEY secret or abusing the write permissions on pull-requests and checks.

CWE: CWE-829 | OWASP: N/A

Recommendation: Pin the action to an immutable commit SHA, e.g. uses: SquidSec/SquidGate@. Apply the same pinning to actions/checkout@v4.


@DotNetRussell
DotNetRussell merged commit f762a5f into master Aug 1, 2026
2 checks passed
@DotNetRussell
DotNetRussell deleted the chore/squidgate-grok-build-0.1 branch August 1, 2026 12:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant