Repository navigation
ci: pin every action to a commit SHA - #59
Merged
Merged
Conversation
…he PyPI token
The publish step handed PYPI_API_TOKEN to pypa/gh-action-pypi-publish@release/v1.
That is a branch, so whoever can push to it decides what code receives a long
lived upload credential for this project, after any review I did of it. A tag
is the same problem with an extra step. A full commit SHA is the only ref that
names fixed content.
Every remote action in ci.yml and release.yml is now pinned to the commit its
latest release tag resolves to (annotated tags dereferenced), with the version
in a trailing comment for Dependabot and for whoever reads the diff:
actions/checkout v7.0.1
actions/setup-python v7.0.0
actions/upload-artifact v4.6.2 (latest v4; majors left to Dependabot)
actions/download-artifact v4.3.0 (same, and the pair must move together)
pypa/gh-action-pypi-publish v1.14.2
dtolnay/rust-toolchain v1, with `toolchain: stable` now explicit,
since `@stable` chose it from the ref name
No behaviour change is intended: every pin stays on the major it already used.
pypi-publish pulls ghcr.io/pypa/gh-action-pypi-publish:<ref>, and that image
exists for the pinned SHA (manifest HEAD returned 200 on 2026-10-10).
tests/test_ci_contract.py gains a guard that every remote `uses:` is a 40 hex
SHA followed by a `# vX` comment. Red proof: against d2317de it fails on
actions/checkout@v7 in ci.yml; with the `# v4.3.0` comment deleted from
download-artifact it fails on the comment assertion. Both green after.
Auth is unchanged: the token stays, as 64cce6b decided. Returning to trusted
publishing once the PyPI publisher record is fixed would remove the token
altogether. The stale "opts into id-token" comment that 64cce6b left at the
top of release.yml is corrected.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The publish step passed
PYPI_API_TOKENtopypa/gh-action-pypi-publish@release/v1, a branch whose owner can change the code that receives the token after I have reviewed it. I pinned every action inci.ymlandrelease.ymlto the commit its release tag resolves to, with the version in a trailing comment so Dependabot keeps the pins current. Every pin stays on the major version it already used.tests/test_ci_contract.pynow fails if any remote action is not pinned to a SHA.I kept the API token from #54. Going back to trusted publishing once the PyPI publisher record is fixed would remove the token entirely, which is the better end state.
🤖 Generated with Claude Code