Repository navigation
ci: pin GitHub Actions to commit SHAs - #421
Conversation
Signed-off-by: Gaurav Chaudhary <chaudharygaurav2004@gmail.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
matthyx
left a comment
There was a problem hiding this comment.
Approve — no blocking findings.
Reviewed d2b39b1e10e5758d36c9c64771571e333f9a5357 against main at 81ccbff2841c84010f50aa02bacb765e6e17eac9. This addresses #417: the target still has 18 mutable external references. The change makes those references immutable without changing triggers, permissions, inputs, or local workflow calls. All seven distinct replacement pins match the original refs' current resolved commits; version comments match upstream tags.
History: no duplicate or superseding pinning PR was found in repository-scoped, all-state searches for pin/workflow/manual-integration-tests/perf-ab/incluster-comp-pr-merged and related SHA/action issues (100 results per query; none hit the limit; indexing and unsearched commit history remain limits). #420 separately changes permissions and overlaps these files. #332's provenance permission is preserved and supported by the pinned release workflow. #52's warning concerned broad permission changes; it does not apply to this diff. #50 deferred Dependabot, not SHA pinning. No explicit prior rejection of this approach was found.
Validation: parsed all six workflow files and compared base/head YAML: exactly 18 uses substitutions, no other semantic changes. Verified all 23 external occurrences (12 distinct refs) resolve in their source repositories and contain the action/workflow metadata; checked changed action inputs and the reusable workflow's required inputs and permission ceiling. actionlint v1.7.12 passed with the existing ubuntu-large label configured and shellcheck/pyflakes disabled; bash -n passed for 25 scripts after substituting GitHub expressions; git diff --no-index --check found no whitespace errors. Base-only actionlint warnings for the two deprecated junit_files inputs are pre-existing; SHA references bypass that built-in diagnostic, and upstream metadata still accepts the input.
CI for this commit: cross-platform build, Basic-Test, CodeQL, DCO, and GitGuardian succeeded; perf-ab was skipped and CodeRabbit did not perform a review. Hosted manual integration, performance, and publishing workflows were not executed locally; repository scripts/actions were not executed. Static equivalence and ref/contract checks are sufficient for this narrowly scoped pinning change. The shared upstream workflow still has mutable transitive dependencies, so this does not establish complete supply-chain immutability. Pins will also require deliberate future updates.
Immediately before submission, the PR remained open, non-draft, conflict-free, and unchanged at the recorded head/base, with no new substantive reviews or inline comments. Required DCO/security checks passed and the head includes the current base; the remaining protection requirement is an approving review. No merge was performed.
Overview
Replace 18 mutable action and reusable workflow references with full 40-character commit SHAs and version or branch comments across the manual integration, performance, and PR-merged workflows.
Preserve existing SHA pins, local reusable workflow references, inputs, permissions, and triggers.
Additional Information
The commit includes a DCO sign-off. Hosted integration and publishing workflows were not executed; no workflows triggered automatically after the fork push.
How to Test
Validation completed:
ubuntu-largerunner label configured.git diff --checkand reviewed the staged diff.Application tests and performance benchmarks were not run because this change only pins workflow references.
Related issues/PRs
Checklist before requesting a review
The unchecked items are not applicable to this workflow-only change.
Target branch:
main