Skip to content

Pin GitHub Actions to commit SHAs and fix go.yml template injection - #15347

Merged
copybara-service[bot] merged 1 commit into
google:masterfrom
milantracy:fix-zizmor-15346
Oct 6, 2026
Merged

copybara-service[bot] merged 1 commit into
google:masterfrom
milantracy:fix-zizmor-15346

Conversation

@milantracy

@milantracy milantracy commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Why

The zizmor check fails on master with 14 error findings (#15346). Eleven are tag-based uses: references, which the blanket pinning policy rejects. Three are ${{ github.event.pull_request.statuses_url }} expanded directly inside run: scripts in go.yml.

Scope

  • Pin actions/checkout@v5, actions/upload-artifact@v4, github/codeql-action/{init,autobuild,analyze}@v4, actions/labeler@v6, and actions/stale@v10 to commit SHAs with a # vX.Y.Z comment, in build.yml, codeql.yml, go.yml, issue_reviver.yml, labeler.yml, and stale.yml.
  • In go.yml, pass statuses_url to the three status steps through env: STATUSES_URL.
  • Out of scope: the medium-severity artipacked warnings, which the check does not enforce.

Blast Radius

Each SHA is the commit the floating major tag resolves to today, so workflows run the same code as before. Dependabot already tracks github-actions and will bump the pins.

Verification

  • zizmor 1.30.1 --offline .github/workflows: 14 errors (14 high) before, 0 errors (0 high) after.
  • git ls-remote confirms each floating major tag (v5, v4, v6, v10) points at the pinned SHA.
  • All workflow files parse as YAML.

Fixes #15346

@google-cla

google-cla Bot commented Oct 6, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Pin every remaining tag reference to the commit its floating major
tag points at today, so runtime behavior does not change.
copybara-service Bot pushed a commit that referenced this pull request Oct 6, 2026
## Why

The zizmor check fails on `master` with 14 error findings (#15346). Eleven are tag-based `uses:` references, which the blanket pinning policy rejects. Three are `${{ github.event.pull_request.statuses_url }}` expanded directly inside `run:` scripts in `go.yml`.

## Scope

- Pin `actions/checkout@v5`, `actions/upload-artifact@v4`, `github/codeql-action/{init,autobuild,analyze}@v4`, `actions/labeler@v6`, and `actions/stale@v10` to commit SHAs with a `# vX.Y.Z` comment, in `build.yml`, `codeql.yml`, `go.yml`, `issue_reviver.yml`, `labeler.yml`, and `stale.yml`.
- In `go.yml`, pass `statuses_url` to the three status steps through `env: STATUSES_URL`.
- Out of scope: the medium-severity `artipacked` warnings, which the check does not enforce.

## Blast Radius

Each SHA is the commit the floating major tag resolves to today, so workflows run the same code as before. Dependabot already tracks `github-actions` and will bump the pins.

## Verification

- `zizmor 1.30.1 --offline .github/workflows`: 14 errors (14 high) before, 0 errors (0 high) after.
- `git ls-remote` confirms each floating major tag (`v5`, `v4`, `v6`, `v10`) points at the pinned SHA.
- All workflow files parse as YAML.

Fixes #15346

FUTURE_COPYBARA_INTEGRATE_REVIEW=#15347 from milantracy:fix-zizmor-15346 e1c9587
PiperOrigin-RevId: 994015654
copybara-service Bot pushed a commit that referenced this pull request Oct 6, 2026
## Why

The zizmor check fails on `master` with 14 error findings (#15346). Eleven are tag-based `uses:` references, which the blanket pinning policy rejects. Three are `${{ github.event.pull_request.statuses_url }}` expanded directly inside `run:` scripts in `go.yml`.

## Scope

- Pin `actions/checkout@v5`, `actions/upload-artifact@v4`, `github/codeql-action/{init,autobuild,analyze}@v4`, `actions/labeler@v6`, and `actions/stale@v10` to commit SHAs with a `# vX.Y.Z` comment, in `build.yml`, `codeql.yml`, `go.yml`, `issue_reviver.yml`, `labeler.yml`, and `stale.yml`.
- In `go.yml`, pass `statuses_url` to the three status steps through `env: STATUSES_URL`.
- Out of scope: the medium-severity `artipacked` warnings, which the check does not enforce.

## Blast Radius

Each SHA is the commit the floating major tag resolves to today, so workflows run the same code as before. Dependabot already tracks `github-actions` and will bump the pins.

## Verification

- `zizmor 1.30.1 --offline .github/workflows`: 14 errors (14 high) before, 0 errors (0 high) after.
- `git ls-remote` confirms each floating major tag (`v5`, `v4`, `v6`, `v10`) points at the pinned SHA.
- All workflow files parse as YAML.

Fixes #15346

FUTURE_COPYBARA_INTEGRATE_REVIEW=#15347 from milantracy:fix-zizmor-15346 e1c9587
PiperOrigin-RevId: 994015654
copybara-service Bot pushed a commit that referenced this pull request Oct 6, 2026
## Why

The zizmor check fails on `master` with 14 error findings (#15346). Eleven are tag-based `uses:` references, which the blanket pinning policy rejects. Three are `${{ github.event.pull_request.statuses_url }}` expanded directly inside `run:` scripts in `go.yml`.

## Scope

- Pin `actions/checkout@v5`, `actions/upload-artifact@v4`, `github/codeql-action/{init,autobuild,analyze}@v4`, `actions/labeler@v6`, and `actions/stale@v10` to commit SHAs with a `# vX.Y.Z` comment, in `build.yml`, `codeql.yml`, `go.yml`, `issue_reviver.yml`, `labeler.yml`, and `stale.yml`.
- In `go.yml`, pass `statuses_url` to the three status steps through `env: STATUSES_URL`.
- Out of scope: the medium-severity `artipacked` warnings, which the check does not enforce.

## Blast Radius

Each SHA is the commit the floating major tag resolves to today, so workflows run the same code as before. Dependabot already tracks `github-actions` and will bump the pins.

## Verification

- `zizmor 1.30.1 --offline .github/workflows`: 14 errors (14 high) before, 0 errors (0 high) after.
- `git ls-remote` confirms each floating major tag (`v5`, `v4`, `v6`, `v10`) points at the pinned SHA.
- All workflow files parse as YAML.

Fixes #15346

FUTURE_COPYBARA_INTEGRATE_REVIEW=#15347 from milantracy:fix-zizmor-15346 e1c9587
PiperOrigin-RevId: 994015654
@copybara-service
copybara-service Bot merged commit b887892 into google:master Oct 6, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

zizmor check is broken

3 participants