Repository navigation
fix(slack-pr-merged): make SHA pins cover the action, redact log refs - #81
Merged
Merged
Conversation
- the reusable workflow called its action at @main, so a caller pinning the workflow to a SHA still ran whatever the action's main was - fetch pipelines at job.workflow_sha (anonymously: the repo is public) and run the action from that checkout Claude-Session: https://claude.ai/code/session_01C7cDTWZqaAjsyvjj8oV6ud
- a failed linked-PR lookup logged the ref and gh's error, which carries the API URL, so a public repo's Actions log could name a private repo and PR number; log only the HTTP status - document that public repos should not get PR_READ_TOKEN Claude-Session: https://claude.ai/code/session_01C7cDTWZqaAjsyvjj8oV6ud
okcan
approved these changes
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Goal
Repos can pin
slack-pr-merged.ymlto a commit SHA and run that commit's code end to end. Public repos can adopt it without their Actions logs naming private PRs.Problem it solves
A caller that pins the workflow by SHA still runs whatever the action is on
main, because the workflow callsslack-pr-merged@main. A later push tomainwould run with the caller's Slack token without the caller ever re-pinning. That is why CodeQL ("Unpinned tag for a non-immutable Action or reusable workflow") and review bots flag callers that pin everything else by SHA.Separately, when a lookup of a linked PR fails on a rate limit or a 5xx, the log line prints the PR reference and
gh's error, which includes the API URL. In a public repo that log is public, so it can name a private repo and PR number.What changes
job.workflow_sha, the commit of the workflow file that defines the job, and runs the action from there. The fetch is anonymous because this repo is public, so callers need no extra permission.@<sha> # main). The README and template say not to givePR_READ_TOKENto a public repo, because it is a credential that reads private PRs.Notes
job.workflow_repositoryandjob.workflow_shaas unknown. Both are documented, and the linter is behind (rhysd/actionlint#707). CI here does not run actionlint.