Skip to content

chore: fleet-wide SHA-pinned dependency staleness audit (SHA pins never get Dependabot security alerts) #257

Description

@kyle-sexton

From the 2026-07-26 claude-review-lanes interview (decision record: .work/claude-review-lanes/interview-checklist.md, Brief: docs/topics/claude-review-lanes/PLAN.md).

Problem

Verified Dependabot mechanics: SHA-pinned actions never produce Dependabot security alerts ("Dependabot ... will not create alerts for actions pinned to SHA values"), and security updates are triggered by alerts — so for a SHA-pinning org, every security-relevant action bump arrives as an ordinary version update, subject to cooldown (a 3-day default applies since 2026-07-14 even with no cooldown block), grouping, and the open-PR budget. anthropics/claude-code-action gets a cooldown exemption in this effort; the rest of the fleet's pinned dependencies have not been audited for equivalent staleness/exposure.

Related real-world precedent: CVE-2026-47751 was delivered to floating-tag users automatically; SHA-pinned users needed their own bump.

Task

Fleet-wide audit (subagent team run is fine) across all melodic-software repos:

  1. Inventory every SHA-pinned uses: (actions + reusable workflows) and every in-workflow tool-version constant invisible to Dependabot (the tool-version-drift-check.yml class).
  2. For each: current pin age vs upstream latest; whether Dependabot/renovate covers it; cooldown/grouping delay it is subject to; whether it is security-sensitive (token handling, runs on privileged triggers).
  3. Output: per-repo findings + recommended cooldown exemptions / drift-check additions; wire into the standards conventions where a policy is warranted.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-humanHuman-in-the-loop required; autonomous sessions must not resolve items carrying this.priority: mediumReal value, no hard deadline; normal backlog flow.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions