Skip to content

CI: pin every action to a commit SHA - #750

Merged
wingleeio merged 1 commit into
mainfrom
ci/pin-actions
Oct 2, 2026
Merged

wingleeio merged 1 commit into
mainfrom
ci/pin-actions

Conversation

@wingleeio

@wingleeio wingleeio commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Every third-party uses: in .github/workflows/ and .github/actions/ (60 references, 8 actions) now names a commit SHA, with the release version as a trailing comment. release.yml runs Swatinem/rust-cache and softprops/action-gh-release next to the macOS signing/notarization secrets and with contents: write; a moved tag could have run new code there.
  • No behavior change: each SHA is the commit the tag (@v2, @v4, @v8) points to today, checked through both the GitHub API and git ls-remote against the action's own repository (so no fork-network commit).
  • .github/dependabot.yml updates the pins weekly as one grouped PR (root workflows and the composite actions).
action version sha
actions/checkout v4.4.0 11d5960a
actions/cache (restore/save) v4.3.0 0057852b
actions/setup-node v4.4.0 49933ea5
actions/upload-artifact v4.6.2 ea165f8d
actions/download-artifact v4.3.0 d3f86a10
actions/github-script v8.0.0 ed597411
Swatinem/rust-cache v2.9.2 6323deb1
softprops/action-gh-release v2.6.2 3bb12739

Test plan

  • actionlint clean on every workflow.
  • No unpinned third-party reference remains.
  • CI on this PR.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Tags like @v2 can be moved by whoever controls the action's repository, and
release.yml runs these actions next to the macOS signing and notarization
secrets. Each reference now names the commit its tag points to today (version
in a trailing comment), so CI runs the same code as before. Dependabot opens
one grouped PR a week to move the pins.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@wingleeio
wingleeio merged commit 69e64ef into main Oct 2, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant