Skip to content

[DSO-3726] Pin workflow actions to SHAs, add lint-actions - #18

Merged
rezaramadhan merged 2 commits into
mainfrom
chore/pin-sha-lint-library-1
Sep 16, 2026
Merged

rezaramadhan merged 2 commits into
mainfrom
chore/pin-sha-lint-library-1

Conversation

@rezaramadhan

@rezaramadhan rezaramadhan commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • SHA-pinned every third-party/action uses: in .github/workflows/ci.yml and .github/workflows/main.yml, staying within the major version each already referenced (no upgrades). Each pin carries a comment with the exact upstream release tag.
  • Replaced the hand-rolled actionlint job in .github/workflows/pull-request.yml with the org's shared lint-actions reusable workflow.
  • .github/workflows/sbom.yml is already SHA-pinned by Dependabot (comments intentionally lack a space, e.g. #v7.0.1) and was left byte-identical to avoid churn Dependabot would otherwise revert.
  • No .github/actionlint.yml existed, so step 3 (delete local actionlint config) was a no-op.
  • No if: conditions exist anywhere in .github/workflows/, so the always-true if: fix did not apply.
  • The only $GITHUB_OUTPUT redirect in the repo (ci.yml) was already correctly quoted.

Updated

  • .github/workflows/ci.yml — pinned actions/checkout (→ v7.0.1), shivammathur/setup-php (@v2 → 2.37.2), actions/cache (@v6 → v6.1.0), actions/upload-artifact (@v7 → v7.0.1) to commit SHAs with tag comments.
  • .github/workflows/main.yml — pinned actions/checkout (→ v7.0.1), actions/download-artifact (@v8 → v8.0.1), SonarSource/sonarqube-scan-action (→ v8.2.1) to commit SHAs with tag comments.
  • .github/workflows/pull-request.yml — removed the hand-rolled actionlint job (checkout + download-actionlint.bash) and added lint-actions, calling Accredifysg/Accredify-Github-Workflows/.github/workflows/lint-actions.yml@236229089b518f5ccc8ad5f0251ea187879cc10f # v2.1.7.

Unchanged (verified, no action needed)

  • .github/workflows/sbom.yml — already SHA-pinned; left byte-identical per Dependabot ownership convention.
  • Local ./.github/workflows/ci.yml references in main.yml and pull-request.yml — not pinnable, left as-is.

🤖 Generated with Claude Code

Jira: https://accredify.atlassian.net/browse/DSO-3726

…tions

Pin every uses: in ci.yml and main.yml to a full commit SHA with the
exact upstream release tag as a comment, staying within the major
version each action already referenced (no upgrades). Replace the
hand-rolled actionlint job in pull-request.yml with the org's shared
Accredifysg/Accredify-Github-Workflows lint-actions reusable workflow,
pinned to v2.1.7. sbom.yml is already SHA-pinned by Dependabot and is
left untouched.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@rezaramadhan rezaramadhan changed the title Pin workflow actions to SHAs, add lint-actions [DSO-3726] Pin workflow actions to SHAs, add lint-actions Sep 16, 2026
Public repos cannot call reusable workflows stored in the internal
Accredify-Github-Workflows repo, which caused these PRs to fail at
workflow startup with zero jobs created. Replace the reusable-workflow
call in pull-request.yml with a local .github/workflows/lint-actions.yml
containing the same Actionlint and Zizmor jobs, using only public
actions, so checks run identically without depending on the internal repo.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@rezaramadhan
rezaramadhan merged commit 3b8ca4e into main Sep 16, 2026
6 checks passed
@rezaramadhan
rezaramadhan deleted the chore/pin-sha-lint-library-1 branch September 16, 2026 06:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants