From 46ed0d090878209a358e1eef50ab5fdcb77b39ec Mon Sep 17 00:00:00 2001 From: Eugene Kim Date: Thu, 10 Sep 2026 18:36:11 +0000 Subject: [PATCH] ci: pin GitHub Actions and PyPI build tooling versions Refine the CI and release workflow setup for reproducibility: - pin every action ref (uses:) in all workflows to a full commit SHA, keeping the currently-used versions - pin pip and build to exact versions in the publish workflow - record SHA-256 digests of the built artifacts in the release log Co-authored-by: Cursor --- .github/workflows/build-test.yml | 8 ++++++-- .github/workflows/check-codegen.yml | 8 ++++++-- .github/workflows/check-vendor.yml | 6 +++++- .github/workflows/python-publish.yml | 21 ++++++++++++++++----- 4 files changed, 33 insertions(+), 10 deletions(-) diff --git a/.github/workflows/build-test.yml b/.github/workflows/build-test.yml index 9657249..7b91246 100644 --- a/.github/workflows/build-test.yml +++ b/.github/workflows/build-test.yml @@ -3,6 +3,10 @@ name: Build and Test +# All action refs (uses:) in this repository must be pinned to full commit +# SHAs, never mutable tags or branches, so CI and release runs are +# reproducible. + on: push: branches: [ "main", "release/*" ] @@ -28,9 +32,9 @@ jobs: - "3.14" steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@a37ce9120846195fa4ece8f58b268e6043cb2f26 # v3.7.0 - name: Set up ${{ matrix.python-version }} - uses: actions/setup-python@v3 + uses: actions/setup-python@3542bca2639a428e1796aaa6a2ffef0c0f575566 # v3.1.4 with: python-version: ${{ matrix.python-version }} - name: Install dependencies diff --git a/.github/workflows/check-codegen.yml b/.github/workflows/check-codegen.yml index 5f79026..c153ddf 100644 --- a/.github/workflows/check-codegen.yml +++ b/.github/workflows/check-codegen.yml @@ -4,6 +4,10 @@ name: Check Codegen +# All action refs (uses:) in this repository must be pinned to full commit +# SHAs, never mutable tags or branches, so CI and release runs are +# reproducible. + on: push: branches: [ "main" ] @@ -24,9 +28,9 @@ jobs: check-codegen: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@a37ce9120846195fa4ece8f58b268e6043cb2f26 # v3.7.0 - name: Set up Python - uses: actions/setup-python@v3 + uses: actions/setup-python@3542bca2639a428e1796aaa6a2ffef0c0f575566 # v3.1.4 with: python-version: "3.11" - name: Run codegen script diff --git a/.github/workflows/check-vendor.yml b/.github/workflows/check-vendor.yml index dc521fb..515fd85 100644 --- a/.github/workflows/check-vendor.yml +++ b/.github/workflows/check-vendor.yml @@ -4,6 +4,10 @@ name: Check OTLP Proto Common Vendored Code +# All action refs (uses:) in this repository must be pinned to full commit +# SHAs, never mutable tags or branches, so CI and release runs are +# reproducible. + on: push: branches: [ "main" ] @@ -22,7 +26,7 @@ jobs: check-codegen: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@a37ce9120846195fa4ece8f58b268e6043cb2f26 # v3.7.0 - name: Run vendor script run: | rm -rf src/snowflake/telemetry/_internal/opentelemetry/exporter/ diff --git a/.github/workflows/python-publish.yml b/.github/workflows/python-publish.yml index 72a940a..cca0257 100644 --- a/.github/workflows/python-publish.yml +++ b/.github/workflows/python-publish.yml @@ -8,6 +8,10 @@ name: Upload Python Package +# All action refs (uses:) in this repository must be pinned to full commit +# SHAs, never mutable tags or branches, so CI and release runs are +# reproducible. + on: release: types: [published] @@ -21,19 +25,26 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Set up Python - uses: actions/setup-python@v3 + uses: actions/setup-python@3542bca2639a428e1796aaa6a2ffef0c0f575566 # v3.1.4 with: python-version: '3.x' - name: Install dependencies + # Pin the build toolchain so release builds are reproducible. + # Bump deliberately. run: | - python -m pip install --upgrade pip - pip install build + python -m pip install pip==26.2.1 + pip install build==1.6.1 - name: Build package run: python -m build + - name: Record artifact digests + # Bind the built artifacts to SHA-256 digests in the release log, so + # the published files can later be compared against what this job + # actually produced. Fails the release if the build produced nothing. + run: sha256sum dist/* - name: Publish package - uses: pypa/gh-action-pypi-publish@release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 with: user: __token__ password: ${{ secrets.PYPI_API_TOKEN }}