Skip to content

ci: pin every action reference to a commit SHA - #178

Open
singlerider wants to merge 1 commit into
devfrom
chore/pin-actions-sha
Open

singlerider wants to merge 1 commit into
devfrom
chore/pin-actions-sha

Conversation

@singlerider

Copy link
Copy Markdown
Collaborator

What

Every uses: reference in this repository is now pinned to a full
40-character commit SHA, with the tag preserved as a trailing comment.
runs-on: ubuntu-latest becomes ubuntu-24.04.

Why

A tag is a mutable pointer the upstream owner can move, and whatever
bytes it resolves to run with this workflow's token. The same applies to
a floating runner label. Pinning submodules and image digests elsewhere
in the family while CI's own code floats leaves that work decorative.

The tag stays on as a trailing comment so Dependabot can still read the
version and bump the pin in place. The github-actions ecosystem is
already enabled here, so the pins stay maintained without extra process.

Floating references removed

Across the family this pass also removes @stable (dtolnay/rust-toolchain),
@latest (medyagh/setup-minikube), @main on our own CLA reusable
workflow, and both release/v1* branches on the PyPI publish path.

Validation

  • Every non-comment uses: in this repo resolves to a 40-character SHA
  • No ubuntu-latest remains
  • All workflow YAML parses
  • SHAs resolved against the GitHub git-ref API, annotated tags
    dereferenced to their target commit

Commented-out references were deliberately left alone.

Refs #149

A tag is a mutable pointer the upstream owner can move, and whatever
bytes it resolves to run with the workflow token. Every `uses:` now
names a full 40-character commit SHA, with the tag kept as a trailing
comment so Dependabot can still read the version and bump the pin.

This also removes the last floating references: `@stable`, `@latest`,
`@main` on our own CLA reusable workflow, and the two
`release/v1*` branches on the PyPI publish path.

Runners move from ubuntu-latest to ubuntu-24.04 for the same reason.
A floating runner label is an unfixed input like any other.

Refs #149
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant