Skip to content

chore: use grok-build-0.1 for SquidGate - #1

Open
DotNetRussell wants to merge 2 commits into
masterfrom
chore/squidgate-grok-build-0.1
Open

chore: use grok-build-0.1 for SquidGate#1
DotNetRussell wants to merge 2 commits into
masterfrom
chore/squidgate-grok-build-0.1

Conversation

@DotNetRussell

Copy link
Copy Markdown
Collaborator

Point SquidGate at xAI grok-build-0.1 (custom provider, api.x.ai). Uses LLM_API_KEY repo secret.

@github-actions

github-actions Bot commented Aug 1, 2026

Copy link
Copy Markdown

🛡️ Security Scan Results

One supply chain issue detected: third-party GitHub Action is not pinned to a commit SHA.

⛔ 1 finding(s) block merge.

HIGH — Unpinned third-party GitHub Action

File: .github/workflows/squidgate.yml:21 | Confidence: high | Category: supply_chain

The workflow uses the external action 'SquidSec/SquidGate@v1' referenced by a mutable tag instead of a specific commit SHA. This creates a supply chain risk where an attacker could compromise the tag to inject malicious code into the CI pipeline.

CWE: CWE-829 | OWASP: N/A

Recommendation: Pin the action to an immutable commit SHA, e.g. 'uses: SquidSec/SquidGate@'. Use Dependabot, Renovate, or similar to manage updates and review changes.


Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant