Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
56 commits
Select commit Hold shift + click to select a range
92d160c
feat: add `atmos pro commit` for server-side commits via GitHub App
osterman Apr 7, 2026
a40b84c
fix: add nil guard for HTTPClient in sendCommitRequest
osterman Apr 7, 2026
611f078
fix: hide GitHubHeadRef from describe config output
osterman Apr 7, 2026
d871abb
fix: reject Unix absolute paths on Windows in validatePath
osterman Apr 7, 2026
34bb851
test: increase pkg/pro coverage from 71.9% to 82.3%
osterman Apr 9, 2026
f5e8587
feat: add atmos-pro.yaml workflow to replace autofix.ci with `atmos p…
osterman Apr 9, 2026
5c95f25
fix: run atmos-pro workflow in container with atmos pre-installed
osterman Apr 9, 2026
ff0dd8b
fix: pin atmos container image to v1.214.0
osterman Apr 9, 2026
59d4ed3
chore: rename workflow from atmos-pro.ci to atmos.ci
osterman Apr 9, 2026
c73314a
fix: pass GITHUB_TOKEN for --use-version PR artifact download
osterman Apr 9, 2026
bb735d7
fix: use container atmos for toolchain and `go run .` for pro commit
osterman Apr 9, 2026
aff6fd6
fix: create .tool-versions before toolchain install in CI
osterman Apr 9, 2026
4c9b537
fix: initialize I/O context in pro commit tests
osterman Apr 9, 2026
b200c94
fix: use owner/repo format for gofumpt in .tool-versions
osterman Apr 9, 2026
59eebed
fix: commit .tool-versions instead of generating it in CI
osterman Apr 9, 2026
7f363a7
fix: set CGO_ENABLED=0 for go run in CI workflow
osterman Apr 9, 2026
5ed7adf
chore: add ATMOS_LOGS_LEVEL=debug to pro commit step
osterman Apr 9, 2026
fbb14de
fix: skip stacks directory validation for pro commit command
osterman Apr 9, 2026
d1738db
feat: fail fast on missing Atmos Pro authentication in pro commit
osterman Apr 9, 2026
e081196
fix: split go build from pro commit execution for better diagnostics
osterman Apr 10, 2026
5724607
fix: pass ATMOS_PRO_WORKSPACE_ID from repository variables to workflow
osterman Apr 10, 2026
f639ea7
fix: set GOFLAGS=-buildvcs=false for container build step
osterman Apr 10, 2026
237bf26
fix: auto-trust GITHUB_WORKSPACE as git safe.directory in containers
osterman Apr 10, 2026
22862fc
refactor: move EnsureGitSafeDirectory to pkg/git
osterman Apr 10, 2026
6925979
feat: enable color output in CI environments by default
osterman Apr 10, 2026
61ee463
test: blank LICENSE and add README regeneration to CI workflow
osterman Apr 10, 2026
3d153ef
feat: add verify-sha-pinning action to detect supply chain attacks
osterman Apr 10, 2026
41e09df
fix: enable markdown color in CI and fix snapshot test failures
osterman Apr 10, 2026
f23515d
feat: add forensics and sticky PR comments to verify-sha-pinning
osterman Apr 10, 2026
587cee3
[autocommit] formatting fixes
atmos-pro[bot] Apr 11, 2026
189dbc3
feat: add IsPiped terminal detection and conditionally output commit SHA
osterman Apr 11, 2026
7b45bb5
Merge remote-tracking branch 'origin/main' into osterman/pro-commit-cmd
osterman Apr 11, 2026
6146a21
docs: use container job in pro commit blog quick start example
osterman Apr 11, 2026
a906f3c
docs: use atmos toolchain exec for terraform in blog example
osterman Apr 11, 2026
5090e99
docs: improve pro commit blog post accuracy
osterman Apr 11, 2026
9634b5e
ci: add terraform fmt for test fixture HCL in atmos-pro workflow
osterman Apr 11, 2026
af916b4
ci: switch to opentofu for HCL formatting in CI
osterman Apr 11, 2026
f1455f3
chore: add tofu alias to toolchain config
osterman Apr 11, 2026
0b940ed
fix: use tofu alias in .tool-versions for toolchain resolution
osterman Apr 11, 2026
a846651
docs: update blog post to use tofu and atmos toolchain exec
osterman Apr 11, 2026
1dfa74b
ci: add tofu fmt for examples/ folder in atmos-pro workflow
osterman Apr 11, 2026
9a5e907
style: tofu fmt test fixture HCL alignment
osterman Apr 11, 2026
5eaf8eb
[autocommit] formatting fixes
atmos-pro[bot] Apr 11, 2026
64332de
docs: pin atmos container image to 1.214.0 in blog example
osterman Apr 11, 2026
2f0f59d
[autocommit] formatting fixes
atmos-pro[bot] Apr 11, 2026
6fe3962
[autocommit] formatting fixes
atmos-pro[bot] Apr 11, 2026
a53db03
[autocommit] formatting fixes
atmos-pro[bot] Apr 11, 2026
62eca02
[autocommit] formatting fixes
atmos-pro[bot] Apr 11, 2026
e58fb9c
test: regenerate golden snapshots for log level and error rendering
osterman Apr 11, 2026
13556f3
fix: set NO_COLOR in tests broken by CI-aware styled rendering
osterman Apr 11, 2026
f45bf7b
fix: exclude regex101.com from link checker to fix CI flake
osterman Apr 11, 2026
ca2e7dd
fix: use cross-platform temp dir in git safe directory test
osterman Apr 11, 2026
b560de2
test: set NO_COLOR in log-level tests and regenerate snapshots
osterman Apr 11, 2026
332b569
fix: restore accidentally deleted LICENSE file
osterman Apr 12, 2026
d65585f
[autocommit] formatting fixes
atmos-pro[bot] Apr 12, 2026
2dddf1f
Merge branch 'main' into osterman/pro-commit-cmd
aknysh Apr 12, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .atmos.d/toolchain.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
toolchain:
aliases:
gofumpt: mvdan/gofumpt
tofu: opentofu/opentofu
registries:
- name: aqua
type: aqua
priority: 10
69 changes: 69 additions & 0 deletions .github/actions/verify-sha-pinning/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
# Verify SHA Pinning

Verifies that SHA-pinned GitHub Actions in workflow files match the tag claimed in their version comment.

## Why

SHA pinning (e.g., `actions/checkout@de0fac2e... # v6.0.2`) is a supply chain security best practice — but only if the SHA actually corresponds to the claimed tag. Attackers can [force-push tags to malicious commits](https://rosesecurity.dev/2026/03/20/typosquatting-trivy.html), making the version comment a lie while the SHA points to compromised code.

This action catches:
- **SHA/tag mismatch** — pinned SHA doesn't match what the upstream tag resolves to
- **Stale pins** — tag was moved upstream (force-push) after initial pinning
- **Typosquatting** — tag not found because the owner/repo is wrong

On mismatch, the action investigates whether the pinned SHA exists in the claimed repo and what tags (if any) it corresponds to — helping distinguish stale pins from supply chain attacks.

## Usage

```yaml
permissions:
contents: read
pull-requests: write

steps:
- uses: actions/checkout@v6
- uses: ./.github/actions/verify-sha-pinning
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
```
**Note:** `pull-requests: write` is required for posting sticky PR comments.

## Inputs

| Input | Required | Default | Description |
|-------|----------|---------|-------------|
| `github-token` | Yes | — | GitHub token for API calls and PR comments |
| `workflow-dir` | No | `.github/workflows` | Directory to scan |

## Outputs

| Output | Description |
|--------|-------------|
| `verified-count` | Number of SHA-pinned actions verified |
| `failed-count` | Number of mismatches found |
| `status` | `pass` or `fail` |

## PR Comments

On pull requests, the action posts a sticky comment (updated in place):
- **Failure**: Warning table with each action's status and forensic details
- **Resolved**: Updated to show all pins verified

No comment is posted on clean PRs that have never had a violation.

## What it scans

Any line in `*.yml` / `*.yaml` matching:

```
uses: owner/repo@<40-char-sha> # v<tag>
```

Handles sub-actions (`owner/repo/sub@sha # tag`) and both annotated and lightweight git tags.

## Local testing

```bash
GITHUB_TOKEN=$(gh auth token) node .github/actions/verify-sha-pinning/test.mjs
```
Loading
Loading