처음이어도 괜찮아요 · 그림부터 시작해요
Action을 full SHA로 고정하고 최소 권한을 준다
third-party action은 검토한 commit SHA로 고정하고 workflow/job permissions를 read 기본과 필요한 write scope로 최소화한다. 이를 생략하면 moving tag와 broad write-all token이 compromised action 또는 untrusted PR에서 repository·artifact를 변경할 수 있다. 상황에서도 데모는 보일 수 있지만 제품·검증·운영 책임을 방어할 수 없습니다.
아직 답을 몰라도 괜찮아요. 아래 작은 예시를 보고 먼저 예상해 보세요.01 · 가볍게 시작하기
정답을 보기 전에 먼저 골라볼까요?
cp45 frozen synthetic fixture · fixed clock/UTC · outbound deny · secret-like sentinel · one independent mutant- 1먼저 골라보기
틀려도 괜찮아요. 지금 생각한 답 하나를 정해요.
- 2그림으로 확인하기
움직이는 순서와 달라지는 곳만 천천히 찾아요.
- 3내 말로 다시 말하기
한 문장으로 말해 보면 내가 이해한 곳을 확인할 수 있어요.
02 · 그림으로 보기
그림이 움직이는 순서를 직접 확인해요
- 01관찰full commit SHA · least privilege · GITHUB_TOKEN · permissions
- 02추론third-party action은 검토한 commit SHA로 고정하고 workflow/job permissions를 read 기본과 필요한 write scope로 최소화한다. action ref→commit review map·permissions diff·write attempt negative test·token scope receipt는 moving tag와 broad write-all token이 compromised action 또는 untrusted PR에서 repository·artifact를 변경할 수 있다.를 포함한 정상·경계·실패 실행에서 독립적으로 다시 계산할 수 있어야 한다. Action을 full SHA로 고정하고 최소 권한을 준다은 AI-off 기준선을 먼저 봉인하고 AI 제안 diff를 검토한 뒤, AI가 보지 못한 mutant로 재검증하고 사람이 승인·수정·거절한다. test·build·attestation을 수행하는 supply-chain CI로 전이할 때 구현보다 contract·effect boundary·evidence owner·residual risk를 먼저 보존한다.
- 03검증Action을 full SHA로 고정하고 최소 권한을 준다의 contract·owner·normal/boundary/failure outcome을 AI 없이 먼저 고정한다. moving tag와 broad write-all token이 compromised action 또는 untrusted PR에서 repository·artifact를 변경할 수 있다.를 frozen synthetic fixture로 재현하고 최초 divergence와 expected verdict를 설명한다. AI 제안은 baseline과 diff로만 검토하고 독립 mutant에서 moving action ref와 과도한 GITHUB_TOKEN permission을 거부하는 workflow security auditor를 구현한다.을 다시 실행한다. action ref→commit review map·permissions diff·write attempt negative test·token scope receipt와 사람의 accept·refactor·reject 판정 및 residual risk를 함께 제출한다.
처음 보는 말도 책 읽듯 풀어봐요
이 수업은 쉬운 뜻과 생활 예를 아직 함께 준비하지 못했어요. 설명 없는 정확한 이름은 먼저 보여 주지 않을게요.
그림에서 찾을 쉬운 규칙
- 01third-party action은 검토한 commit SHA로 고정하고 workflow/job permissions를 read 기본과 필요한 write scope로 최소화한다.
- 02action ref→commit review map·permissions diff·write attempt negative test·token scope receipt는 moving tag와 broad write-all token이 compromised action 또는 untrusted PR에서 repository·artifact를 변경할 수 있다.를 포함한 정상·경계·실패 실행에서 독립적으로 다시 계산할 수 있어야 한다.
- 03Action을 full SHA로 고정하고 최소 권한을 준다은 AI-off 기준선을 먼저 봉인하고 AI 제안 diff를 검토한 뒤, AI가 보지 못한 mutant로 재검증하고 사람이 승인·수정·거절한다.
- 04test·build·attestation을 수행하는 supply-chain CI로 전이할 때 구현보다 contract·effect boundary·evidence owner·residual risk를 먼저 보존한다.
03 · 같이 풀어보기
한 단계씩 따라가면 어렵지 않아요
test·build·attestation을 수행하는 supply-chain CI의 축소된 product slice에서 Action을 full SHA로 고정하고 최소 권한을 준다 release 판단을 수행한다.
cp45 frozen synthetic fixture · fixed clock/UTC · outbound deny · secret-like sentinel · one independent mutant04 · 이제 내가 해볼 차례
여기까지 오면 이런 일을 할 수 있어요
moving action ref와 과도한 GITHUB_TOKEN permission을 거부하는 workflow security auditor를 구현한다.을 수행하고 action ref→commit review map·permissions diff·write attempt negative test·token scope receipt로 third-party action은 검토한 commit SHA로 고정하고 workflow/job permissions를 read 기본과 필요한 write scope로 최소화한다.을 독립 검증한다.
- Action을 full SHA로 고정하고 최소 권한을 준다의 contract·owner·normal/boundary/failure outcome을 AI 없이 먼저 고정한다.
- moving tag와 broad write-all token이 compromised action 또는 untrusted PR에서 repository·artifact를 변경할 수 있다.를 frozen synthetic fixture로 재현하고 최초 divergence와 expected verdict를 설명한다.
- AI 제안은 baseline과 diff로만 검토하고 독립 mutant에서 moving action ref와 과도한 GITHUB_TOKEN permission을 거부하는 workflow security auditor를 구현한다.을 다시 실행한다.
- action ref→commit review map·permissions diff·write attempt negative test·token scope receipt와 사람의 accept·refactor·reject 판정 및 residual risk를 함께 제출한다.
05 · 자주 헷갈리는 지점
틀린 답도 이유를 알면 다음에는 맞힐 수 있어요
01공식 action의 major tag는 full SHA와 같은 immutability를 제공한다.
한 번 더 생각해 볼 질문cp45 Action을 full SHA로 고정하고 최소 권한을 준다에서 이 주장을 깨는 최소 반례와 관찰 가능한 판정값을 쓰세요.
이렇게 고쳐 생각해요third-party action은 검토한 commit SHA로 고정하고 workflow/job permissions를 read 기본과 필요한 write scope로 최소화한다.
02permissions를 생략하면 read-only가 항상 적용된다.
한 번 더 생각해 볼 질문cp45 Action을 full SHA로 고정하고 최소 권한을 준다에서 이 주장을 깨는 최소 반례와 관찰 가능한 판정값을 쓰세요.
이렇게 고쳐 생각해요moving tag와 broad write-all token이 compromised action 또는 untrusted PR에서 repository·artifact를 변경할 수 있다.는 성공 출력과 별도로 재현하고 최초 위반 지점에서 차단해야 한다.
03AI가 유명 action을 골랐으면 source commit 검토는 필요 없다.
한 번 더 생각해 볼 질문cp45 Action을 full SHA로 고정하고 최소 권한을 준다에서 이 주장을 깨는 최소 반례와 관찰 가능한 판정값을 쓰세요.
이렇게 고쳐 생각해요action ref→commit review map·permissions diff·write attempt negative test·token scope receipt와 독립 mutant·human verdict가 함께 있어야 승인 범위를 설명할 수 있다.
06 · 더 궁금할 때만 보기
선생님과 검토자를 위한 믿을 만한 원문
원문과 어디까지 참고했는지 펼쳐 보기처음 배우는 동안에는 열지 않아도 괜찮아요.
event·job·matrix·concurrency·environment·permissions를 versioned workflow contract로 표현하고 명시되지 않은 권한을 최소화한다.
job-scoped repository token과 최소 권한. ephemeral token이 workflow logic이나 dependency를 자동으로 안전하게 만들지는 않는다.
component inventory·build environment·package management·provenance 관련 선택 control과 공급망 evidence gap
