Repository navigation
Pin GitHub Actions to commit SHAs and fix go.yml template injection - #15347
Merged
Merged
Conversation
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
EtiennePerot
approved these changes
Oct 6, 2026
relkochta
approved these changes
Oct 6, 2026
Pin every remaining tag reference to the commit its floating major tag points at today, so runtime behavior does not change.
milantracy
force-pushed
the
fix-zizmor-15346
branch
from
October 6, 2026 00:42
c1322b2 to
e1c9587
Compare
EtiennePerot
approved these changes
Oct 6, 2026
copybara-service Bot
pushed a commit
that referenced
this pull request
Oct 6, 2026
## Why The zizmor check fails on `master` with 14 error findings (#15346). Eleven are tag-based `uses:` references, which the blanket pinning policy rejects. Three are `${{ github.event.pull_request.statuses_url }}` expanded directly inside `run:` scripts in `go.yml`. ## Scope - Pin `actions/checkout@v5`, `actions/upload-artifact@v4`, `github/codeql-action/{init,autobuild,analyze}@v4`, `actions/labeler@v6`, and `actions/stale@v10` to commit SHAs with a `# vX.Y.Z` comment, in `build.yml`, `codeql.yml`, `go.yml`, `issue_reviver.yml`, `labeler.yml`, and `stale.yml`. - In `go.yml`, pass `statuses_url` to the three status steps through `env: STATUSES_URL`. - Out of scope: the medium-severity `artipacked` warnings, which the check does not enforce. ## Blast Radius Each SHA is the commit the floating major tag resolves to today, so workflows run the same code as before. Dependabot already tracks `github-actions` and will bump the pins. ## Verification - `zizmor 1.30.1 --offline .github/workflows`: 14 errors (14 high) before, 0 errors (0 high) after. - `git ls-remote` confirms each floating major tag (`v5`, `v4`, `v6`, `v10`) points at the pinned SHA. - All workflow files parse as YAML. Fixes #15346 FUTURE_COPYBARA_INTEGRATE_REVIEW=#15347 from milantracy:fix-zizmor-15346 e1c9587 PiperOrigin-RevId: 994015654
copybara-service Bot
pushed a commit
that referenced
this pull request
Oct 6, 2026
## Why The zizmor check fails on `master` with 14 error findings (#15346). Eleven are tag-based `uses:` references, which the blanket pinning policy rejects. Three are `${{ github.event.pull_request.statuses_url }}` expanded directly inside `run:` scripts in `go.yml`. ## Scope - Pin `actions/checkout@v5`, `actions/upload-artifact@v4`, `github/codeql-action/{init,autobuild,analyze}@v4`, `actions/labeler@v6`, and `actions/stale@v10` to commit SHAs with a `# vX.Y.Z` comment, in `build.yml`, `codeql.yml`, `go.yml`, `issue_reviver.yml`, `labeler.yml`, and `stale.yml`. - In `go.yml`, pass `statuses_url` to the three status steps through `env: STATUSES_URL`. - Out of scope: the medium-severity `artipacked` warnings, which the check does not enforce. ## Blast Radius Each SHA is the commit the floating major tag resolves to today, so workflows run the same code as before. Dependabot already tracks `github-actions` and will bump the pins. ## Verification - `zizmor 1.30.1 --offline .github/workflows`: 14 errors (14 high) before, 0 errors (0 high) after. - `git ls-remote` confirms each floating major tag (`v5`, `v4`, `v6`, `v10`) points at the pinned SHA. - All workflow files parse as YAML. Fixes #15346 FUTURE_COPYBARA_INTEGRATE_REVIEW=#15347 from milantracy:fix-zizmor-15346 e1c9587 PiperOrigin-RevId: 994015654
copybara-service Bot
pushed a commit
that referenced
this pull request
Oct 6, 2026
## Why The zizmor check fails on `master` with 14 error findings (#15346). Eleven are tag-based `uses:` references, which the blanket pinning policy rejects. Three are `${{ github.event.pull_request.statuses_url }}` expanded directly inside `run:` scripts in `go.yml`. ## Scope - Pin `actions/checkout@v5`, `actions/upload-artifact@v4`, `github/codeql-action/{init,autobuild,analyze}@v4`, `actions/labeler@v6`, and `actions/stale@v10` to commit SHAs with a `# vX.Y.Z` comment, in `build.yml`, `codeql.yml`, `go.yml`, `issue_reviver.yml`, `labeler.yml`, and `stale.yml`. - In `go.yml`, pass `statuses_url` to the three status steps through `env: STATUSES_URL`. - Out of scope: the medium-severity `artipacked` warnings, which the check does not enforce. ## Blast Radius Each SHA is the commit the floating major tag resolves to today, so workflows run the same code as before. Dependabot already tracks `github-actions` and will bump the pins. ## Verification - `zizmor 1.30.1 --offline .github/workflows`: 14 errors (14 high) before, 0 errors (0 high) after. - `git ls-remote` confirms each floating major tag (`v5`, `v4`, `v6`, `v10`) points at the pinned SHA. - All workflow files parse as YAML. Fixes #15346 FUTURE_COPYBARA_INTEGRATE_REVIEW=#15347 from milantracy:fix-zizmor-15346 e1c9587 PiperOrigin-RevId: 994015654
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The zizmor check fails on
masterwith 14 error findings (#15346). Eleven are tag-baseduses:references, which the blanket pinning policy rejects. Three are${{ github.event.pull_request.statuses_url }}expanded directly insiderun:scripts ingo.yml.Scope
actions/checkout@v5,actions/upload-artifact@v4,github/codeql-action/{init,autobuild,analyze}@v4,actions/labeler@v6, andactions/stale@v10to commit SHAs with a# vX.Y.Zcomment, inbuild.yml,codeql.yml,go.yml,issue_reviver.yml,labeler.yml, andstale.yml.go.yml, passstatuses_urlto the three status steps throughenv: STATUSES_URL.artipackedwarnings, which the check does not enforce.Blast Radius
Each SHA is the commit the floating major tag resolves to today, so workflows run the same code as before. Dependabot already tracks
github-actionsand will bump the pins.Verification
zizmor 1.30.1 --offline .github/workflows: 14 errors (14 high) before, 0 errors (0 high) after.git ls-remoteconfirms each floating major tag (v5,v4,v6,v10) points at the pinned SHA.Fixes #15346