Skip to content

Action pins: exact release tag in every version comment (D-331) - #178

Merged
okieselbach merged 2 commits into
mainfrom
fix/action-pin-exact-versions
Oct 8, 2026
Merged

okieselbach merged 2 commits into
mainfrom
fix/action-pin-exact-versions

Conversation

@okieselbach

Copy link
Copy Markdown
Owner

Why

actions/setup-node v7.1.0 and actions/upload-artifact v7.0.2 moved the floating v7 tag. Our pins still point at v7.0.0 and v7.0.1, which is correct, but their # v7 comments no longer named the pinned commit. zizmor's ref-version-mismatch audit then raised 11 code-scanning alerts on main. The five other pins with a major-only comment (checkout, setup-dotnet, cache, attest-build-provenance, functions-action) would fail the same way at their next upstream release.

What

  • All 38 major-only comments now name the exact release tag of their pinned SHA. No SHA changed; Dependabot keeps updating the SHA and the comment together.

    Action Comment
    actions/checkout # v7.0.1
    actions/setup-dotnet # v6.0.0
    actions/cache # v6.1.0
    actions/setup-node # v7.0.0
    actions/upload-artifact # v7.0.1
    actions/attest-build-provenance # v4.2.2
    Azure/functions-action # v1.5.7
  • verify-pins in action-pins.yml now accepts only a # vX.Y.Z comment and reports a floating major with its own error. The header comment explains the rule. (D-331, which amends the comment form of D-226)

Verification

  • zizmor in online mode (GH_TOKEN set) reproduced exactly the 11 findings before the change and reports 0 ref-version-mismatch after. zizmor --min-severity low . exits 0.
  • The verify-pins script passes all 51 uses: lines. In a scratch workflow it rejects a major-only comment, a missing comment and a tag reference, and accepts an exact tag followed by a trailing note.

After merge, the Workflow gates run on main should move alerts #97–#107 to fixed.

🤖 Generated with Claude Code

okieselbach and others added 2 commits October 8, 2026 13:57
setup-node v7.1.0 and upload-artifact v7.0.2 moved the floating v7 tag, so the
"# v7" comments on our still-correct pins (v7.0.0, v7.0.1) stopped naming the
pinned commit and zizmor's ref-version-mismatch raised 11 code-scanning
alerts on main. The other five major-only comments (checkout, setup-dotnet,
cache, attest-build-provenance, functions-action) were one upstream release
away from the same alert.

All 38 major-only comments now carry the tag their unchanged SHA resolves to
(checkout v7.0.1, setup-dotnet v6.0.0, cache v6.1.0, setup-node v7.0.0,
upload-artifact v7.0.1, attest-build-provenance v4.2.2, functions-action
v1.5.7); no SHA moved, Dependabot keeps advancing SHA and comment together.
verify-pins now accepts only a vX.Y.Z comment and names the floating-major
case in its own error.

Verified: zizmor online (GH_TOKEN) reproduced the 11 findings before and
reports 0 ref-version-mismatch after, --min-severity low exits 0; the
verify-pins script passes all 51 uses lines and rejects a major-only comment,
a missing comment and a tag reference in a scratch workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@okieselbach
okieselbach merged commit be0e370 into main Oct 8, 2026
12 checks passed
@okieselbach
okieselbach deleted the fix/action-pin-exact-versions branch October 10, 2026 16:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant