feat(ci): Security hardening - SLSA Level 3 compliance and Renovate migration - #53
Merged
Conversation
…igration - Pin all GitHub Actions to immutable SHA digests (SLSA Level 3) - Add Renovate configuration with corrected lux.toml regex and github-tags datasource (no native luarocks datasource exists) - Map busted, luacov, luastatic to their canonical GitHub repos - Add SBOM generation (anchore/sbom-action) for linux-x86_64 only - Add build provenance attestation (actions/attest-build-provenance) - Add update-release-notes job with attestation verification instructions - Add luarocks-publish environment to publish workflow - Fix indentation in publish.yml rockspec cleanup step - Preserve paths-ignore in release-please workflow - No permission changes to tests.yml (inherits repo default read)
tkolleh
enabled auto-merge (squash)
April 19, 2026 05:54
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR implements the security hardening plan to bring the CI/CD pipeline to SLSA Level 3 compliance and migrates from Dependabot to Renovate for dependency management.
Changes
Renovate Configuration (
renovate.json- new)config:recommendedand:dependencyDashboardpresetsgithub-actionsmanager withpinDigests: truefor SHA pinningcustomManagersregex forlux.tomldependency detection usinggithub-tagsdatasource (no nativeluarocksdatasource exists in Renovate)busted→lunarmodules/busted,luacov→lunarmodules/luacov,luastatic→ers35/luastaticversion,package,lua,license) from matchingWorkflow Security Hardening
.github/workflows/tests.ymlread).github/workflows/release-please.ymlpaths-ignoreconfigurationpermissionsblock tobuild-releasejob only:contents: write,id-token: write,attestations: writeanchore/sbom-action@v0.17.0(linux-x86_64 only)actions/attest-build-provenance@v1.4.3(linux-x86_64 only)update-release-notesjob that appends attestation verification instructions to releases.github/workflows/publish.ymlenvironment: luarocks-publishfor secret protectionrm -f "$ROCKSPEC"lineread)GitHub Environment
luarocks-publishenvironment (viagh api)Verification
All action SHAs have been verified against the GitHub API to match their claimed version tags:
actions/checkout11bd71901bbe5b1630ceea73d27597364c9af683lumen-oss/gh-actions-lux60bee431bba7e65b608b8aa309be0eb0252f5e79extractions/setup-justdd310ad5a97d8e7b41793f8ef055398d51ad4de6googleapis/release-please-action7987652d64b4581673a76e33ad5e98e3dd56832fmsys2/setup-msys2ddf331adaebd714795f1042345e6ca57bd66cea8anchore/sbom-actiond94f46e13c6c62f59525ac9a1e147a99dc0b9bf5actions/attest-build-provenance1c608d11d69870c2092266b3f9a6f3abbf17002c