Skip to content

Pin GitHub Actions to commit SHAs - #3259

Open
github-security-bot wants to merge 3 commits into
mainfrom
pinner/actions-sha-pins-2026-09-10
Open

github-security-bot wants to merge 3 commits into
mainfrom
pinner/actions-sha-pins-2026-09-10

Conversation

@github-security-bot

@github-security-bot github-security-bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Pins direct external GitHub Actions references to immutable commit SHAs while preserving their current versions and channels in comments.

Conflict resolution

  • Incorporated current main (71ef8266) without reverting upstream changes.
  • Reapplied 34 pins across 12 workflows, preserving the current CodeQL v4.38.2 steps, Docker publish jobs, newer action versions, and existing SHA pins.
  • Preserved reusable-workflow calls and same-repository references.
  • Retained the seven-day GitHub Actions Dependabot cooldown and every existing update entry, including the new npm entry for /ui.

Validation

  • Resolved current-base action tags/branches through the GitHub API.
  • Verified workflow semantics are unchanged except for action references and Dependabot entries are preserved.
  • Verified exact remote contents and the diff against current main; the branch includes both its previous head and current base, with zero commits behind.
  • No application fixes or policy changes. CI results remain visible in the PR checks; conflict resolution does not claim that all checks pass.

Copilot AI balanced review requested due to automatic review settings September 10, 2026 21:28
@github-security-bot
github-security-bot requested a review from a team as a code owner September 10, 2026 21:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The local build-ui composite action still contains two mutable external action references.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Pins direct workflow action dependencies to immutable SHAs and adds a Dependabot update cooldown.

Changes:

  • Pins 34 workflow action references with version comments.
  • Adds a seven-day GitHub Actions cooldown.
File summaries
File Description
.github/workflows/registry-releaser.yml Pins checkout and Go setup.
.github/workflows/moderator.yml Pins checkout and moderation actions.
.github/workflows/mcp-diff.yml Pins checkout and Go setup.
.github/workflows/lint.yml Pins lint workflow actions.
.github/workflows/license-check.yml Pins license-check actions.
.github/workflows/goreleaser.yml Pins release and attestation actions.
.github/workflows/go.yml Pins build workflow actions.
.github/workflows/docs-check.yml Pins documentation-check actions.
.github/workflows/docker-publish.yml Pins checkout and cache actions.
.github/workflows/code-scanning.yml Pins CodeQL and setup actions.
.github/workflows/close-inactive-issues.yml Pins the stale action.
.github/workflows/ai-issue-assessment.yml Pins checkout.
.github/dependabot.yml Adds a seven-day cooldown.
Review details
  • Files reviewed: 13/13 changed files
  • Comments generated: 1
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/lint.yml Outdated
- name: Build UI
uses: ./.github/actions/build-ui
- uses: actions/setup-go@v7
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
@tiagovilasboas

Copy link
Copy Markdown

Staff AppSec (Actions SHA pinning)

Verdict: Approve with a small follow-up (conversation comment — formal review UI often disabled here.)

Pinning 34 workflow uses: refs to full commit SHAs (+ Dependabot github-actions 7-day cooldown) is the right supply-chain default: tag retargets can no longer silently change CI. Comment style is Dependabot-friendly.

Please follow up (or amend): .github/actions/build-ui/action.yml still uses mutable actions/cache@v5 and actions/setup-node@v6. That composite is on the hot path for go/lint/docs/license/code-scanning/goreleaser/mcp-diff — pinning workflows alone leaves a second mutable hop. Same # vX.Y.Z comment style as the rest of this PR.

Otherwise LGTM from AppSec.

@SamMorrowDrums SamMorrowDrums added the github_actions Pull requests that update GitHub Actions code label Sep 12, 2026
mrecachinas
mrecachinas previously approved these changes Oct 6, 2026
Preserve current-base workflow jobs, action versions, existing pins, and Dependabot entries; reapply only the PR's pinning and cooldown intent.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants