Skip to content

fix: pin GitHub Actions to commit hashes - #1015

Merged
matthyx merged 1 commit into
kubescape:mainfrom
ANAMASGARD:fix/996-pin-github-actions-by-commit
Oct 5, 2026
Merged

matthyx merged 1 commit into
kubescape:mainfrom
ANAMASGARD:fix/996-pin-github-actions-by-commit

Conversation

@ANAMASGARD

@ANAMASGARD ANAMASGARD commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Overview

Replace 36 mutable action references across eight CI workflows with verified full 40-character commit hashes. All 37 external action references are now pinned, preventing tag or branch changes from silently changing the actions used by CI.

Preserve the currently resolved action versions, existing SHA pin, and local reusable-workflow references. Add revision comments for provenance.

Additional Information

Workflow inputs, permissions, triggers, and jobs remain unchanged.

Local Scorecard confirms all 23 GitHub-owned and 14 third-party action references are pinned. The overall Pinned-Dependencies score increased from 0/10 to 5/10; remaining findings concern existing Docker images, pip dependencies, Go installation, and download-and-run commands.

Existing workflow diagnostics remain outside this pinning-only change. Hosted CI was not executed because no workflows triggered on the branch push.

How to Test

Validation performed:

  • Verified every unique pinned commit belongs to its source repository and contains the referenced action metadata.
  • Inspected supplied inputs and documented the existing unsupported benchmark comment-tag input.
  • Parsed all 10 workflow files and confirmed that only intended action revisions changed.
  • Confirmed every external action reference uses a full commit hash.
  • Ran actionlint: no new diagnostics compared with the baseline.
  • Ran local Scorecard Pinned-Dependencies checks.
  • Ran git diff --check and reviewed the staged diff.

Go tests were not run because application code is unchanged.

Related issues/PRs

Checklist before requesting a review

  • My code follows the style guidelines of this project
  • I have commented on my code, particularly in hard-to-understand areas
  • I have performed a self-review of my code
  • If it is a core feature, I have added thorough tests.
  • New and existing unit tests pass locally with my changes

The unchecked items are not applicable to this workflow-reference-only change. The commit includes a DCO sign-off.

Summary by CodeRabbit

  • Chores
    • CI workflows now use fixed versions of their actions, making the actions used in automated checks and release processes consistent. Workflow behavior is unchanged.

Signed-off-by: Gaurav Chaudhary <chaudharygaurav2004@gmail.com>
@ANAMASGARD
ANAMASGARD requested a review from matthyx October 5, 2026 05:50
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c761ccec-ab79-4637-bd4b-44bf765b64f6
📥 Commits

Reviewing files that changed from the base of the PR and between 67e455e and 2e38bc4.

📒 Files selected for processing (8)
  • .github/workflows/benchmark.yaml
  • .github/workflows/bypass.yaml
  • .github/workflows/check-ig-pin.yaml
  • .github/workflows/component-tests.yaml
  • .github/workflows/go-basic-tests.yaml
  • .github/workflows/incluster-comp-pr-merged.yaml
  • .github/workflows/pr-merged.yaml
  • .github/workflows/scorecard.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Eight GitHub Actions workflows now reference actions by commit SHA instead of mutable tags or a branch. Existing workflow configuration, conditions, and version comments remain unchanged.

Changes

Workflow action pinning

Layer / File(s) Summary
Pin actions in test workflows
.github/workflows/benchmark.yaml, .github/workflows/check-ig-pin.yaml, .github/workflows/component-tests.yaml, .github/workflows/go-basic-tests.yaml
These workflows now use commit-pinned references for checkout, language setup, artifact, CodeQL, and other actions.
Pin actions in merge and release workflows
.github/workflows/bypass.yaml, .github/workflows/pr-merged.yaml, .github/workflows/incluster-comp-pr-merged.yaml
Build-number, merge, and release workflow actions now use commit-pinned references.
Pin actions in Scorecard workflow
.github/workflows/scorecard.yml
Checkout, Scorecard, artifact upload, and SARIF upload actions now use commit-pinned references.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested reviewers: matthyx

Merge Risk: ⚪ Minimal · up to 2e38b

The workflows now pin actions to fixed commits instead of moving references. No concrete workflow regression is established, so there is no demonstrated merge-blocking impact.

Architecture Summary

Architecture risk: 🔵 Low · up to 2e38b

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/benchmark.yaml: The checkout and Go setup steps now reference pinned action commit SHAs instead of version tags; their checkout depth and Go configuration remain unchanged.
  • observed — Modified behavior in .github/workflows/benchmark.yaml: The Python setup step now references a pinned action commit SHA instead of the v5 tag.
  • observed — Modified behavior in .github/workflows/benchmark.yaml: The PR comment step now references a pinned action commit SHA instead of the v4 tag.
  • observed — Modified behavior in .github/workflows/benchmark.yaml: The artifact upload step now references a pinned action commit SHA instead of the v4 tag.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: pinning GitHub Actions to commit hashes across CI workflows.
Linked Issues check ✅ Passed Issue [#996] requires the identified GitHub Actions references to use full 40-character commit hashes with version comments. The PR summary reports that all 37 external action references are pinned an…
Out of Scope Changes check ✅ Passed The PR changes action references in eight CI workflows. The additional workflow pins use the same immutable-reference change requested by issue [#996]. The summaries report no changes to workflow beha…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
✨ Finishing Touches 💡 1
🧪 Generate unit tests (beta)
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@matthyx matthyx left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve reviewed commit 2e38bc48b523d839eec0754db69f31563fc3f74d against main at 67e455e040520a3f1f5a4ac20fbf5fe25f676d43. No introduced blockers found; independent code review recommends approval and architecture review is CLEAR.

The change is needed: #996 explicitly requests full action SHA pins to prevent mutable tags changing executable CI dependencies. The current target still has 36 mutable references; this PR pins those while preserving the existing pin, making all 37 external references immutable. It directly addresses that cause without changing permissions, triggers, inputs, commands, jobs, or local reusable-workflow references.

History: searched repository PRs across open/closed/merged states using pin, GitHub Actions, scorecard, commit hash, benchmark.yaml, and incluster-comp-pr-merged.yaml, plus related issue searches (100-result maximum per query; indexed text search cannot prove absence). No duplicate or superseding action-pinning PR found. #1011 changes token permissions and is complementary. Merged #200 upgraded checkout; merged #228 updated Scorecard. The latter had a bot suggestion favoring readable tags, not a maintainer rejection of SHA pins; revision comments preserve readability and #996 now explicitly requires pins. Related closed workflow #827 was closed because it targeted the wrong repository, not because maintainers rejected pinning. No applicable prior maintainer rejection found.

Validation performed on exact base/head workflow snapshots:

  • Parsed all 10 YAML files and compared normalized text: only action revisions/comments changed. All 37 external references match the full 40-character SHA requirement.
  • Queried upstream commits and action metadata for every unique action path: all 36 replacements equal the original tag/branch's currently resolved commit; every referenced action has metadata at its SHA, including subdirectory actions.
  • Ran actionlint -shellcheck= -pyflakes= -oneline against base and head: eight baseline diagnostics versus three head diagnostics, with no new diagnostics. Five tag-specific warnings disappear because SHA refs bypass actionlint's built-in lookup; they are not demonstrated fixes. Metadata inspection confirms the unsupported benchmark comment-tag and Node 16 setup-go v4/CodeQL v2 runtimes preexist unchanged.
  • git diff --no-index --check produced no whitespace diagnostics (exit 1 reflects differing snapshots).

No repository code or action code was executed locally; no hosted workflows were triggered. Go tests are outside this workflow-reference-only scope. Scorecard's claimed score improvement was not independently rerun. At submission, pin check, image build, DCO, and security checks had passed; component CI remained running. Current branch protection/rules require a latest-push approval and specify no required status checks. Runtime behavior of release, benchmark, and fork-only paths was not exercised; exact upstream revision equivalence supplies the relevant compatibility evidence for this mechanical change.

Remaining maintenance consideration: pins require reviewed updates; no in-repository Dependabot/Renovate setup was found. Transitive downloads/images remain outside this scope. Neither is an introduced blocker.

Immediately before submission, confirmed OPEN, non-draft, MERGEABLE, unchanged head/target, and no existing review or inline blocker to duplicate. Approval applies to this commit; CI completion and final merge remain with maintainers.

@matthyx
matthyx merged commit 04a7bfe into kubescape:main Oct 5, 2026
35 of 36 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: To Archive

Development

Successfully merging this pull request may close these issues.

Pin GitHub Actions by commit hash in CI workflows

2 participants