Skip to content

fix(slack-pr-merged): make SHA pins cover the action, redact log refs - #81

Merged
klaidliadon merged 2 commits into
mainfrom
fix/slack-pr-merged-pinnable
Oct 8, 2026
Merged

klaidliadon merged 2 commits into
mainfrom
fix/slack-pr-merged-pinnable

Conversation

@klaidliadon

@klaidliadon klaidliadon commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Goal

Repos can pin slack-pr-merged.yml to a commit SHA and run that commit's code end to end. Public repos can adopt it without their Actions logs naming private PRs.

Problem it solves

A caller that pins the workflow by SHA still runs whatever the action is on main, because the workflow calls slack-pr-merged@main. A later push to main would run with the caller's Slack token without the caller ever re-pinning. That is why CodeQL ("Unpinned tag for a non-immutable Action or reusable workflow") and review bots flag callers that pin everything else by SHA.

Separately, when a lookup of a linked PR fails on a rate limit or a 5xx, the log line prints the PR reference and gh's error, which includes the API URL. In a public repo that log is public, so it can name a private repo and PR number.

What changes

  • The script comes from the workflow's own commit. The job fetches this repo at job.workflow_sha, the commit of the workflow file that defines the job, and runs the action from there. The fetch is anonymous because this repo is public, so callers need no extra permission.
  • Failed lookups log only the HTTP status. The PR reference and URL stay out of the log.
  • Docs. The trigger template recommends a SHA pin (@<sha> # main). The README and template say not to give PR_READ_TOKEN to a public repo, because it is a credential that reads private PRs.

Notes

  • actionlint 1.7.12 reports job.workflow_repository and job.workflow_sha as unknown. Both are documented, and the linter is behind (rhysd/actionlint#707). CI here does not run actionlint.
  • This repo's own trigger runs the new fetch step when this PR merges. Check that run is green before consumers pin to the merge SHA.

- the reusable workflow called its action at @main, so a caller pinning
  the workflow to a SHA still ran whatever the action's main was
- fetch pipelines at job.workflow_sha (anonymously: the repo is public)
  and run the action from that checkout

Claude-Session: https://claude.ai/code/session_01C7cDTWZqaAjsyvjj8oV6ud
- a failed linked-PR lookup logged the ref and gh's error, which carries
  the API URL, so a public repo's Actions log could name a private repo
  and PR number; log only the HTTP status
- document that public repos should not get PR_READ_TOKEN

Claude-Session: https://claude.ai/code/session_01C7cDTWZqaAjsyvjj8oV6ud
@klaidliadon klaidliadon changed the title fix(slack-pr-merged): run the action from the workflow's own commit fix(slack-pr-merged): make the workflow pinnable and safe for public repos Oct 8, 2026
@klaidliadon klaidliadon changed the title fix(slack-pr-merged): make the workflow pinnable and safe for public repos fix(slack-pr-merged): make SHA pins cover the action, redact log refs Oct 8, 2026
@klaidliadon
klaidliadon merged commit 76d8bf3 into main Oct 8, 2026
10 checks passed
@klaidliadon
klaidliadon deleted the fix/slack-pr-merged-pinnable branch October 8, 2026 09:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants