Repository navigation
fix: pin GitHub Actions to commit hashes - #1015
Conversation
Signed-off-by: Gaurav Chaudhary <chaudharygaurav2004@gmail.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (8)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughEight GitHub Actions workflows now reference actions by commit SHA instead of mutable tags or a branch. Existing workflow configuration, conditions, and version comments remain unchanged. ChangesWorkflow action pinning
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The workflows now pin actions to fixed commits instead of moving references. No concrete workflow regression is established, so there is no demonstrated merge-blocking impact. Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🧪 Generate unit tests (beta)
🛠️ Fix failing CI checks 💡
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
matthyx
left a comment
There was a problem hiding this comment.
Approve reviewed commit 2e38bc48b523d839eec0754db69f31563fc3f74d against main at 67e455e040520a3f1f5a4ac20fbf5fe25f676d43. No introduced blockers found; independent code review recommends approval and architecture review is CLEAR.
The change is needed: #996 explicitly requests full action SHA pins to prevent mutable tags changing executable CI dependencies. The current target still has 36 mutable references; this PR pins those while preserving the existing pin, making all 37 external references immutable. It directly addresses that cause without changing permissions, triggers, inputs, commands, jobs, or local reusable-workflow references.
History: searched repository PRs across open/closed/merged states using pin, GitHub Actions, scorecard, commit hash, benchmark.yaml, and incluster-comp-pr-merged.yaml, plus related issue searches (100-result maximum per query; indexed text search cannot prove absence). No duplicate or superseding action-pinning PR found. #1011 changes token permissions and is complementary. Merged #200 upgraded checkout; merged #228 updated Scorecard. The latter had a bot suggestion favoring readable tags, not a maintainer rejection of SHA pins; revision comments preserve readability and #996 now explicitly requires pins. Related closed workflow #827 was closed because it targeted the wrong repository, not because maintainers rejected pinning. No applicable prior maintainer rejection found.
Validation performed on exact base/head workflow snapshots:
- Parsed all 10 YAML files and compared normalized text: only action revisions/comments changed. All 37 external references match the full 40-character SHA requirement.
- Queried upstream commits and action metadata for every unique action path: all 36 replacements equal the original tag/branch's currently resolved commit; every referenced action has metadata at its SHA, including subdirectory actions.
- Ran
actionlint -shellcheck= -pyflakes= -onelineagainst base and head: eight baseline diagnostics versus three head diagnostics, with no new diagnostics. Five tag-specific warnings disappear because SHA refs bypass actionlint's built-in lookup; they are not demonstrated fixes. Metadata inspection confirms the unsupported benchmarkcomment-tagand Node 16 setup-go v4/CodeQL v2 runtimes preexist unchanged. git diff --no-index --checkproduced no whitespace diagnostics (exit 1 reflects differing snapshots).
No repository code or action code was executed locally; no hosted workflows were triggered. Go tests are outside this workflow-reference-only scope. Scorecard's claimed score improvement was not independently rerun. At submission, pin check, image build, DCO, and security checks had passed; component CI remained running. Current branch protection/rules require a latest-push approval and specify no required status checks. Runtime behavior of release, benchmark, and fork-only paths was not exercised; exact upstream revision equivalence supplies the relevant compatibility evidence for this mechanical change.
Remaining maintenance consideration: pins require reviewed updates; no in-repository Dependabot/Renovate setup was found. Transitive downloads/images remain outside this scope. Neither is an introduced blocker.
Immediately before submission, confirmed OPEN, non-draft, MERGEABLE, unchanged head/target, and no existing review or inline blocker to duplicate. Approval applies to this commit; CI completion and final merge remain with maintainers.
Overview
Replace 36 mutable action references across eight CI workflows with verified full 40-character commit hashes. All 37 external action references are now pinned, preventing tag or branch changes from silently changing the actions used by CI.
Preserve the currently resolved action versions, existing SHA pin, and local reusable-workflow references. Add revision comments for provenance.
Additional Information
Workflow inputs, permissions, triggers, and jobs remain unchanged.
Local Scorecard confirms all 23 GitHub-owned and 14 third-party action references are pinned. The overall Pinned-Dependencies score increased from 0/10 to 5/10; remaining findings concern existing Docker images, pip dependencies, Go installation, and download-and-run commands.
Existing workflow diagnostics remain outside this pinning-only change. Hosted CI was not executed because no workflows triggered on the branch push.
How to Test
Validation performed:
comment-taginput.git diff --checkand reviewed the staged diff.Go tests were not run because application code is unchanged.
Related issues/PRs
Checklist before requesting a review
The unchecked items are not applicable to this workflow-reference-only change. The commit includes a DCO sign-off.
Summary by CodeRabbit