Skip to content

ci: pin GitHub Actions to commit SHAs - #421

Merged
matthyx merged 1 commit into
kubescape:mainfrom
ANAMASGARD:fix/417-pin-github-actions-by-commit
Oct 5, 2026
Merged

matthyx merged 1 commit into
kubescape:mainfrom
ANAMASGARD:fix/417-pin-github-actions-by-commit

Conversation

@ANAMASGARD

Copy link
Copy Markdown
Member

Overview

Replace 18 mutable action and reusable workflow references with full 40-character commit SHAs and version or branch comments across the manual integration, performance, and PR-merged workflows.

Preserve existing SHA pins, local reusable workflow references, inputs, permissions, and triggers.

Additional Information

The commit includes a DCO sign-off. Hosted integration and publishing workflows were not executed; no workflows triggered automatically after the fork push.

How to Test

Validation completed:

  • Verified all 23 external references resolve to commits in their source repositories and contain the referenced actions or workflows.
  • Checked action inputs, reusable workflow contracts, and caller permissions.
  • Confirmed all six workflows parse and the only YAML semantic changes are the 18 revision substitutions.
  • Checked syntax for 25 embedded shell scripts.
  • Ran actionlint v1.7.12: no new diagnostics; passed with the existing custom ubuntu-large runner label configured.
  • Ran git diff --check and reviewed the staged diff.

Application tests and performance benchmarks were not run because this change only pins workflow references.

Related issues/PRs

Checklist before requesting a review

  • My code follows the style guidelines of this project
  • I have commented on my code, particularly in hard-to-understand areas
  • I have performed a self-review of my code
  • If it is a core feature, I have added thorough tests.
  • New and existing unit tests pass locally with my changes

The unchecked items are not applicable to this workflow-only change.

Target branch: main

Signed-off-by: Gaurav Chaudhary <chaudharygaurav2004@gmail.com>
@ANAMASGARD
ANAMASGARD requested a review from matthyx October 5, 2026 06:49
@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 8d6567f2-aadd-47e1-9df4-ed47095b5cc7
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@matthyx matthyx left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve — no blocking findings.

Reviewed d2b39b1e10e5758d36c9c64771571e333f9a5357 against main at 81ccbff2841c84010f50aa02bacb765e6e17eac9. This addresses #417: the target still has 18 mutable external references. The change makes those references immutable without changing triggers, permissions, inputs, or local workflow calls. All seven distinct replacement pins match the original refs' current resolved commits; version comments match upstream tags.

History: no duplicate or superseding pinning PR was found in repository-scoped, all-state searches for pin/workflow/manual-integration-tests/perf-ab/incluster-comp-pr-merged and related SHA/action issues (100 results per query; none hit the limit; indexing and unsearched commit history remain limits). #420 separately changes permissions and overlaps these files. #332's provenance permission is preserved and supported by the pinned release workflow. #52's warning concerned broad permission changes; it does not apply to this diff. #50 deferred Dependabot, not SHA pinning. No explicit prior rejection of this approach was found.

Validation: parsed all six workflow files and compared base/head YAML: exactly 18 uses substitutions, no other semantic changes. Verified all 23 external occurrences (12 distinct refs) resolve in their source repositories and contain the action/workflow metadata; checked changed action inputs and the reusable workflow's required inputs and permission ceiling. actionlint v1.7.12 passed with the existing ubuntu-large label configured and shellcheck/pyflakes disabled; bash -n passed for 25 scripts after substituting GitHub expressions; git diff --no-index --check found no whitespace errors. Base-only actionlint warnings for the two deprecated junit_files inputs are pre-existing; SHA references bypass that built-in diagnostic, and upstream metadata still accepts the input.

CI for this commit: cross-platform build, Basic-Test, CodeQL, DCO, and GitGuardian succeeded; perf-ab was skipped and CodeRabbit did not perform a review. Hosted manual integration, performance, and publishing workflows were not executed locally; repository scripts/actions were not executed. Static equivalence and ref/contract checks are sufficient for this narrowly scoped pinning change. The shared upstream workflow still has mutable transitive dependencies, so this does not establish complete supply-chain immutability. Pins will also require deliberate future updates.

Immediately before submission, the PR remained open, non-draft, conflict-free, and unchanged at the recorded head/base, with no new substantive reviews or inline comments. Required DCO/security checks passed and the head includes the current base; the remaining protection requirement is an approving review. No merge was performed.

@matthyx
matthyx merged commit 1ea7103 into kubescape:main Oct 5, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: To Archive

Development

Successfully merging this pull request may close these issues.

Pin GitHub Actions by commit hash in CI workflows

2 participants