Repository navigation
[DSO-3726] Pin workflow actions to SHAs, add lint-actions - #18
Merged
Merged
Conversation
…tions Pin every uses: in ci.yml and main.yml to a full commit SHA with the exact upstream release tag as a comment, staying within the major version each action already referenced (no upgrades). Replace the hand-rolled actionlint job in pull-request.yml with the org's shared Accredifysg/Accredify-Github-Workflows lint-actions reusable workflow, pinned to v2.1.7. sbom.yml is already SHA-pinned by Dependabot and is left untouched. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Public repos cannot call reusable workflows stored in the internal Accredify-Github-Workflows repo, which caused these PRs to fail at workflow startup with zero jobs created. Replace the reusable-workflow call in pull-request.yml with a local .github/workflows/lint-actions.yml containing the same Actionlint and Zizmor jobs, using only public actions, so checks run identically without depending on the internal repo. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
abbavivek
approved these changes
Sep 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
uses:in.github/workflows/ci.ymland.github/workflows/main.yml, staying within the major version each already referenced (no upgrades). Each pin carries a comment with the exact upstream release tag.actionlintjob in.github/workflows/pull-request.ymlwith the org's sharedlint-actionsreusable workflow..github/workflows/sbom.ymlis already SHA-pinned by Dependabot (comments intentionally lack a space, e.g.#v7.0.1) and was left byte-identical to avoid churn Dependabot would otherwise revert..github/actionlint.ymlexisted, so step 3 (delete local actionlint config) was a no-op.if:conditions exist anywhere in.github/workflows/, so the always-trueif:fix did not apply.$GITHUB_OUTPUTredirect in the repo (ci.yml) was already correctly quoted.Updated
.github/workflows/ci.yml— pinnedactions/checkout(→v7.0.1),shivammathur/setup-php(@v2→2.37.2),actions/cache(@v6→v6.1.0),actions/upload-artifact(@v7→v7.0.1) to commit SHAs with tag comments..github/workflows/main.yml— pinnedactions/checkout(→v7.0.1),actions/download-artifact(@v8→v8.0.1),SonarSource/sonarqube-scan-action(→v8.2.1) to commit SHAs with tag comments..github/workflows/pull-request.yml— removed the hand-rolledactionlintjob (checkout +download-actionlint.bash) and addedlint-actions, callingAccredifysg/Accredify-Github-Workflows/.github/workflows/lint-actions.yml@236229089b518f5ccc8ad5f0251ea187879cc10f # v2.1.7.Unchanged (verified, no action needed)
.github/workflows/sbom.yml— already SHA-pinned; left byte-identical per Dependabot ownership convention../.github/workflows/ci.ymlreferences inmain.ymlandpull-request.yml— not pinnable, left as-is.🤖 Generated with Claude Code
Jira: https://accredify.atlassian.net/browse/DSO-3726