Repository navigation
Action pins: exact release tag in every version comment (D-331) - #178
Merged
Merged
Conversation
setup-node v7.1.0 and upload-artifact v7.0.2 moved the floating v7 tag, so the "# v7" comments on our still-correct pins (v7.0.0, v7.0.1) stopped naming the pinned commit and zizmor's ref-version-mismatch raised 11 code-scanning alerts on main. The other five major-only comments (checkout, setup-dotnet, cache, attest-build-provenance, functions-action) were one upstream release away from the same alert. All 38 major-only comments now carry the tag their unchanged SHA resolves to (checkout v7.0.1, setup-dotnet v6.0.0, cache v6.1.0, setup-node v7.0.0, upload-artifact v7.0.1, attest-build-provenance v4.2.2, functions-action v1.5.7); no SHA moved, Dependabot keeps advancing SHA and comment together. verify-pins now accepts only a vX.Y.Z comment and names the floating-major case in its own error. Verified: zizmor online (GH_TOKEN) reproduced the 11 findings before and reports 0 ref-version-mismatch after, --min-severity low exits 0; the verify-pins script passes all 51 uses lines and rejects a major-only comment, a missing comment and a tag reference in a scratch workflow. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
actions/setup-nodev7.1.0 andactions/upload-artifactv7.0.2 moved the floatingv7tag. Our pins still point at v7.0.0 and v7.0.1, which is correct, but their# v7comments no longer named the pinned commit. zizmor'sref-version-mismatchaudit then raised 11 code-scanning alerts onmain. The five other pins with a major-only comment (checkout, setup-dotnet, cache, attest-build-provenance, functions-action) would fail the same way at their next upstream release.What
All 38 major-only comments now name the exact release tag of their pinned SHA. No SHA changed; Dependabot keeps updating the SHA and the comment together.
actions/checkout# v7.0.1actions/setup-dotnet# v6.0.0actions/cache# v6.1.0actions/setup-node# v7.0.0actions/upload-artifact# v7.0.1actions/attest-build-provenance# v4.2.2Azure/functions-action# v1.5.7verify-pinsinaction-pins.ymlnow accepts only a# vX.Y.Zcomment and reports a floating major with its own error. The header comment explains the rule. (D-331, which amends the comment form of D-226)Verification
GH_TOKENset) reproduced exactly the 11 findings before the change and reports 0ref-version-mismatchafter.zizmor --min-severity low .exits 0.verify-pinsscript passes all 51uses:lines. In a scratch workflow it rejects a major-only comment, a missing comment and a tag reference, and accepts an exact tag followed by a trailing note.After merge, the
Workflow gatesrun onmainshould move alerts #97–#107 to fixed.🤖 Generated with Claude Code