Skip to content

ci: pin GitHub Actions to commit SHAs - #55

Merged
desaintmartin merged 1 commit into
masterfrom
ci/pin-actions-sha
Oct 2, 2026
Merged

desaintmartin merged 1 commit into
masterfrom
ci/pin-actions-sha

Conversation

@desaintmartin

Copy link
Copy Markdown
Member

Why

Tags are mutable. A compromised action owner can move a tag and run code with the workflow secrets. A full commit SHA is immutable.

What

  • Pins 6 action references to full commit SHAs. A comment gives the exact release tag.
  • Floating tags (for example @v4) resolve to the newest release in the same major. No major version changes.
  • pypa/gh-action-pypi-publish@release/v1 resolves to v1.14.2, the tip of release/v1.
  • The docker/* actions already had SHAs. They get tag comments: login v1.10.0, metadata v3.3.0, build-push v2.5.0. These versions are old. A separate change can upgrade them.
  • Adds .github/dependabot.yml with the github-actions ecosystem, weekly. Dependabot keeps the SHAs and the tag comments current.

Tags are mutable. A compromised action owner can move a tag and
run code with the workflow secrets. A full SHA is immutable.

Dependabot updates the github-actions ecosystem weekly to keep the
pins current.
@desaintmartin
desaintmartin merged commit 58c8b74 into master Oct 2, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant