Skip to content

Commit e109c1e

Browse files
committed
fix(ci): pin third-party actions to full commit SHAs
The account's Actions policy requires a full-length SHA ref. A tag or branch ref is refused at startup — `startup_failure`, no jobs, "this workflow graph cannot be shown" — so these workflows could not run at all. This resolves each ref to the commit it currently points at and records the ref in a trailing comment, e.g. `actions/checkout@<sha> # v4`. `dtolnay/rust-toolchain` takes its toolchain from the ref itself, so those steps also gained an explicit `with: toolchain:` input; without it, a SHA ref would silently lose the channel. No behaviour is intended to change beyond the pins.
1 parent 76308c9 commit e109c1e

7 files changed

Lines changed: 21 additions & 21 deletions

File tree

‎.github/workflows/cflite_batch.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,14 +20,14 @@ jobs:
2020
steps:
2121
- name: Build Fuzzers (${{ matrix.sanitizer }})
2222
id: build
23-
uses: google/clusterfuzzlite/actions/build_fuzzers@v1
23+
uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
2424
with:
2525
language: rust
2626
sanitizer: ${{ matrix.sanitizer }}
2727

2828
- name: Run Fuzzers (${{ matrix.sanitizer }})
2929
id: run
30-
uses: google/clusterfuzzlite/actions/run_fuzzers@v1
30+
uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
3131
with:
3232
github-token: ${{ secrets.GITHUB_TOKEN }}
3333
fuzz-seconds: 1800

‎.github/workflows/cflite_pr.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,18 +18,18 @@ jobs:
1818
sanitizer: [address]
1919
steps:
2020
- name: Checkout
21-
uses: actions/checkout@v7.0.1
21+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2222

2323
- name: Build Fuzzers (${{ matrix.sanitizer }})
2424
id: build
25-
uses: google/clusterfuzzlite/actions/build_fuzzers@v1
25+
uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
2626
with:
2727
language: rust
2828
sanitizer: ${{ matrix.sanitizer }}
2929

3030
- name: Run Fuzzers (${{ matrix.sanitizer }})
3131
id: run
32-
uses: google/clusterfuzzlite/actions/run_fuzzers@v1
32+
uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
3333
with:
3434
github-token: ${{ secrets.GITHUB_TOKEN }}
3535
fuzz-seconds: 300

‎.github/workflows/codeql.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -39,15 +39,15 @@ jobs:
3939
build-mode: none
4040
steps:
4141
- name: Checkout
42-
uses: actions/checkout@v7.0.1
42+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
4343

4444
- name: Initialize CodeQL
45-
uses: github/codeql-action/init@v4.38.0
45+
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
4646
with:
4747
languages: ${{ matrix.language }}
4848
build-mode: ${{ matrix.build-mode }}
4949

5050
- name: Perform CodeQL Analysis
51-
uses: github/codeql-action/analyze@v4.38.0
51+
uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
5252
with:
5353
category: "/language:${{ matrix.language }}"

‎.github/workflows/language-policy.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
runs-on: ubuntu-latest
2121
timeout-minutes: 15
2222
steps:
23-
- uses: actions/checkout@v7.0.1
23+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2424
- name: Enforce language policies
2525
run: |
2626
# Block new Python files (except SaltStack)

‎.github/workflows/pages.yml‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,9 +21,9 @@ jobs:
2121
image: ghcr.io/stefan-hoeck/idris2-pack@sha256:f0758996a931fb35d9ecb1de273c4d59dabe2a09b433afc7e357f65a08b7e1ff
2222
steps:
2323
- name: Checkout Site
24-
uses: actions/checkout@v7.0.1
24+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2525
- name: Checkout Ddraig SSG
26-
uses: actions/checkout@v7.0.1
26+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2727
with:
2828
repository: hyperpolymath/ddraig-ssg
2929
path: .ddraig-ssg
@@ -40,7 +40,7 @@ jobs:
4040
fi
4141
./.ddraig-ssg/build/exec/ddraig build src _site https://hyperpolymath.github.io/${GITHUB_REPOSITORY#*/}
4242
- name: Upload artifact
43-
uses: actions/upload-pages-artifact@v5.0.0
43+
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
4444
with:
4545
path: '_site'
4646
deploy:
@@ -53,4 +53,4 @@ jobs:
5353
steps:
5454
- name: Deploy to GitHub Pages
5555
id: deployment
56-
uses: actions/deploy-pages@v5.0.1
56+
uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1

‎.github/workflows/proofs.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ jobs:
3939
name: Coq — CNO + OND (14 theories)
4040
runs-on: ubuntu-24.04
4141
steps:
42-
- uses: actions/checkout@v7.0.1
42+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
4343
- name: Install Coq
4444
run: sudo apt-get update && sudo apt-get install -y coq
4545
- name: Build all theories via coq_makefile
@@ -55,7 +55,7 @@ jobs:
5555
runs-on: ubuntu-24.04
5656
timeout-minutes: 25
5757
steps:
58-
- uses: actions/checkout@v7.0.1
58+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
5959
- name: Install Agda (binary only)
6060
# Install just the `agda` binary (2.6.3 on 24.04). NOT `agda-stdlib` —
6161
# the Ubuntu stdlib package ships no usable library manifest; we fetch a
@@ -84,7 +84,7 @@ jobs:
8484
name: Z3 — CNO + OND bounded checks
8585
runs-on: ubuntu-24.04
8686
steps:
87-
- uses: actions/checkout@v7.0.1
87+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
8888
- name: Install Z3
8989
run: sudo apt-get update && sudo apt-get install -y z3
9090
- name: Run Z3 checks

‎.github/workflows/publish-container.yml‎

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -22,18 +22,18 @@ jobs:
2222
id-token: write # mint the OIDC token the attestation is signed with
2323
attestations: write # write the build-provenance attestation (the "claim")
2424
steps:
25-
- uses: actions/checkout@v7.0.1
25+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2626

2727
- name: Log in to GitHub Container Registry
28-
uses: docker/login-action@v4.6.0
28+
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
2929
with:
3030
registry: ghcr.io
3131
username: ${{ github.actor }}
3232
password: ${{ secrets.GITHUB_TOKEN }}
3333

3434
- name: Extract metadata
3535
id: meta
36-
uses: docker/metadata-action@v6.2.0
36+
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
3737
with:
3838
images: ghcr.io/${{ github.repository }}
3939
tags: |
@@ -44,7 +44,7 @@ jobs:
4444
4545
- name: Build and push
4646
id: push
47-
uses: docker/build-push-action@v7.4.0
47+
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
4848
with:
4949
context: .
5050
file: ./Containerfile
@@ -53,7 +53,7 @@ jobs:
5353
labels: ${{ steps.meta.outputs.labels }}
5454

5555
- name: Attest container provenance
56-
uses: actions/attest-build-provenance@v4.2.2
56+
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
5757
with:
5858
subject-name: ghcr.io/${{ github.repository }}
5959
subject-digest: ${{ steps.push.outputs.digest }}

0 commit comments

Comments
 (0)