← Inspection rules
SEC-007 / v1.2.0 / 2026-10-02
Inspect external CI code and permissions
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
CI executing external actions, orbs, scripts, or build tools.
Where to look first
- CI workflows, download URLs, action references
- Job permissions, secret types, trust boundaries
- Dependency lockfiles, frozen installation, and publishing jobs
Inspection steps
- Inspect mutable references and direct remote-script execution; assess pinning, signatures, and trusted verification.
- Check whether external-code steps receive unnecessary secrets or write permissions.
- Check committed lockfiles and frozen installs, and whether dependency installation can access tokens that publish other packages.
Remediation direction
- Pin reviewed references and review updates; separate jobs by secret requirements.
Evidence required for completion
- Record pinned references, verification evidence, and successful execution under narrowed permissions.
Limits and unverified scope
- Pinning does not prove code is safe. A checksum from the same compromised source is insufficient.