Skip to content

ci: pin every action to a commit SHA - #59

Merged
GiulioDER merged 1 commit into
masterfrom
ci/pin-actions-to-commit-shas
Oct 10, 2026
Merged

GiulioDER merged 1 commit into
masterfrom
ci/pin-actions-to-commit-shas

Conversation

@GiulioDER

Copy link
Copy Markdown
Owner

The publish step passed PYPI_API_TOKEN to pypa/gh-action-pypi-publish@release/v1, a branch whose owner can change the code that receives the token after I have reviewed it. I pinned every action in ci.yml and release.yml to the commit its release tag resolves to, with the version in a trailing comment so Dependabot keeps the pins current. Every pin stays on the major version it already used.

tests/test_ci_contract.py now fails if any remote action is not pinned to a SHA.

I kept the API token from #54. Going back to trusted publishing once the PyPI publisher record is fixed would remove the token entirely, which is the better end state.

🤖 Generated with Claude Code

…he PyPI token

The publish step handed PYPI_API_TOKEN to pypa/gh-action-pypi-publish@release/v1.
That is a branch, so whoever can push to it decides what code receives a long
lived upload credential for this project, after any review I did of it. A tag
is the same problem with an extra step. A full commit SHA is the only ref that
names fixed content.

Every remote action in ci.yml and release.yml is now pinned to the commit its
latest release tag resolves to (annotated tags dereferenced), with the version
in a trailing comment for Dependabot and for whoever reads the diff:

  actions/checkout             v7.0.1
  actions/setup-python         v7.0.0
  actions/upload-artifact      v4.6.2   (latest v4; majors left to Dependabot)
  actions/download-artifact    v4.3.0   (same, and the pair must move together)
  pypa/gh-action-pypi-publish  v1.14.2
  dtolnay/rust-toolchain       v1, with `toolchain: stable` now explicit,
                               since `@stable` chose it from the ref name

No behaviour change is intended: every pin stays on the major it already used.
pypi-publish pulls ghcr.io/pypa/gh-action-pypi-publish:<ref>, and that image
exists for the pinned SHA (manifest HEAD returned 200 on 2026-10-10).

tests/test_ci_contract.py gains a guard that every remote `uses:` is a 40 hex
SHA followed by a `# vX` comment. Red proof: against d2317de it fails on
actions/checkout@v7 in ci.yml; with the `# v4.3.0` comment deleted from
download-artifact it fails on the comment assertion. Both green after.

Auth is unchanged: the token stays, as 64cce6b decided. Returning to trusted
publishing once the PyPI publisher record is fixed would remove the token
altogether. The stale "opts into id-token" comment that 64cce6b left at the
top of release.yml is corrected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@GiulioDER
GiulioDER merged commit 800fc1c into master Oct 10, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant