Skip to content

ci: pin GitHub Actions by commit SHA - #5

Merged
pppolf merged 1 commit into
mainfrom
agent/pin-github-actions
Aug 12, 2026
Merged

pppolf merged 1 commit into
mainfrom
agent/pin-github-actions

Conversation

@pppolf

@pppolf pppolf commented Aug 12, 2026

Copy link
Copy Markdown
Member

Summary

  • Pin every third-party action used by the CI workflow to an immutable 40-character commit SHA.
  • Retain the reviewed major-version tag as an inline comment so future updates remain understandable.

Why

GitHub Action major-version tags are mutable. Resolving the exact reviewed revisions in the repository prevents an upstream tag move from changing the code executed with the CI job's contents: read token and checked-out source.

Impact

CI behavior and action major versions are unchanged. Dependency updates must now intentionally replace both the commit SHA and its version comment.

Validation

  • YAML parse with Ruby/Psych
  • actionlint v1.7.12
  • custom check proving all 10 direct uses: references contain a lowercase 40-character SHA and a version comment
  • git diff --check

Audit

  • No workflow permissions, triggers, commands, dependencies, product code, or runtime authority changed.
  • No credentials or local runtime data are included.

@pppolf
pppolf marked this pull request as ready for review August 12, 2026 10:18
@pppolf
pppolf merged commit c6505c3 into main Aug 12, 2026
4 checks passed
@NanaseInori
NanaseInori deleted the agent/pin-github-actions branch September 16, 2026 09:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant