← Inspection rules

SEC-007 / v1.2.0 / 2026-10-02

Inspect external CI code and permissions

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

CI executing external actions, orbs, scripts, or build tools.

Where to look first

  • CI workflows, download URLs, action references
  • Job permissions, secret types, trust boundaries
  • Dependency lockfiles, frozen installation, and publishing jobs

Inspection steps

  1. Inspect mutable references and direct remote-script execution; assess pinning, signatures, and trusted verification.
  2. Check whether external-code steps receive unnecessary secrets or write permissions.
  3. Check committed lockfiles and frozen installs, and whether dependency installation can access tokens that publish other packages.

Remediation direction

  • Pin reviewed references and review updates; separate jobs by secret requirements.

Evidence required for completion

  • Record pinned references, verification evidence, and successful execution under narrowed permissions.

Limits and unverified scope

  • Pinning does not prove code is safe. A checksum from the same compromised source is insufficient.