Skip to content

Commit 2bb487c

Browse files
fix(ci): pin third-party actions to full commit SHAs (#83)
fix(ci): pin third-party actions to full commit SHAs The account's Actions policy requires a full-length SHA ref. A tag or branch ref is refused at startup — `startup_failure`, no jobs, "this workflow graph cannot be shown" — so these workflows could not run at all. This resolves each ref to the commit it currently points at and records the ref in a trailing comment, e.g. `actions/checkout@<sha> # v4`. `dtolnay/rust-toolchain` takes its toolchain from the ref itself, so those steps also gained an explicit `with: toolchain:` input; without it, a SHA ref would silently lose the channel. No behaviour is intended to change beyond the pins.
1 parent 682d696 commit 2bb487c

14 files changed

Lines changed: 31 additions & 31 deletions

‎.github/workflows/boj-build.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ jobs:
1111
timeout-minutes: 15
1212
steps:
1313
- name: Checkout
14-
uses: actions/checkout@v4.1.7
14+
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
1515
- name: Trigger BoJ Server (Casket/ssg-mcp)
1616
run: |
1717
# Send a secure trigger to boj-server to build this repository

‎.github/workflows/cargo-audit.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ jobs:
2020
runs-on: ubuntu-latest
2121
timeout-minutes: 15
2222
steps:
23-
- uses: actions/checkout@v4.1.1
23+
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
2424
- name: Install cargo-audit
2525
run: cargo install cargo-audit --locked
2626
- name: Run cargo audit
@@ -36,7 +36,7 @@ jobs:
3636
permissions:
3737
issues: write
3838
steps:
39-
- uses: actions/checkout@v4.1.1
39+
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
4040
- name: Create vulnerability issue
4141
env:
4242
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}

‎.github/workflows/casket-pages.yml‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -18,11 +18,11 @@ jobs:
1818
timeout-minutes: 15
1919
steps:
2020
- name: Checkout
21-
uses: actions/checkout@v4.1.1
21+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
2222
- name: Setup Pages
23-
uses: actions/configure-pages@v5.0.0
23+
uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5.0.0
2424
- name: Upload artifact
25-
uses: actions/upload-pages-artifact@v3.0.1
25+
uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3.0.1
2626
with:
2727
path: '.'
2828
deploy:
@@ -35,4 +35,4 @@ jobs:
3535
steps:
3636
- name: Deploy to GitHub Pages
3737
id: deployment
38-
uses: actions/deploy-pages@v4.0.5
38+
uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4.0.5

‎.github/workflows/cflite_batch.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,13 +18,13 @@ jobs:
1818
steps:
1919
- name: Build Fuzzers (${{ matrix.sanitizer }})
2020
id: build
21-
uses: google/clusterfuzzlite/actions/build_fuzzers@v1
21+
uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
2222
with:
2323
language: rust
2424
sanitizer: ${{ matrix.sanitizer }}
2525
- name: Run Fuzzers (${{ matrix.sanitizer }})
2626
id: run
27-
uses: google/clusterfuzzlite/actions/run_fuzzers@v1
27+
uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
2828
with:
2929
github-token: ${{ secrets.GITHUB_TOKEN }}
3030
fuzz-seconds: 1800

‎.github/workflows/cflite_pr.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,13 +17,13 @@ jobs:
1717
steps:
1818
- name: Build Fuzzers (${{ matrix.sanitizer }})
1919
id: build
20-
uses: google/clusterfuzzlite/actions/build_fuzzers@v1
20+
uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
2121
with:
2222
language: rust
2323
sanitizer: ${{ matrix.sanitizer }}
2424
- name: Run Fuzzers (${{ matrix.sanitizer }})
2525
id: run
26-
uses: google/clusterfuzzlite/actions/run_fuzzers@v1
26+
uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
2727
with:
2828
github-token: ${{ secrets.GITHUB_TOKEN }}
2929
fuzz-seconds: 300

‎.github/workflows/codeql.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -35,13 +35,13 @@ jobs:
3535
build-mode: none
3636
steps:
3737
- name: Checkout
38-
uses: actions/checkout@v6.0.2
38+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
3939
- name: Initialize CodeQL
40-
uses: github/codeql-action/init@v4.34.0
40+
uses: github/codeql-action/init@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v4.34.0
4141
with:
4242
languages: ${{ matrix.language }}
4343
build-mode: ${{ matrix.build-mode }}
4444
- name: Perform CodeQL Analysis
45-
uses: github/codeql-action/analyze@v4.34.0
45+
uses: github/codeql-action/analyze@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v4.34.0
4646
with:
4747
category: "/language:${{ matrix.language }}"

‎.github/workflows/dependabot-automerge.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ jobs:
5252
steps:
5353
- name: Fetch Dependabot metadata
5454
id: meta
55-
uses: dependabot/fetch-metadata@v2.2.0
55+
uses: dependabot/fetch-metadata@dbb049abf0d677abbd7f7eee0375145b417fdd34 # v2.2.0
5656
with:
5757
github-token: ${{ secrets.GITHUB_TOKEN }}
5858
# --- Policy gate -------------------------------------------------------

‎.github/workflows/dogfood-gate.yml‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727

2828
steps:
2929
- name: Checkout repository
30-
uses: actions/checkout@v4.3.1
30+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
3131

3232
- name: Check for A2ML files
3333
id: detect
@@ -68,7 +68,7 @@ jobs:
6868

6969
steps:
7070
- name: Checkout repository
71-
uses: actions/checkout@v4.3.1
71+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
7272

7373
- name: Check for K9 files
7474
id: detect
@@ -114,7 +114,7 @@ jobs:
114114

115115
steps:
116116
- name: Checkout repository
117-
uses: actions/checkout@v4.3.1
117+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
118118

119119
- name: Scan for invisible characters
120120
id: lint
@@ -207,7 +207,7 @@ jobs:
207207

208208
steps:
209209
- name: Checkout repository
210-
uses: actions/checkout@v4.3.1
210+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
211211

212212
- name: Check for Groove manifest
213213
id: groove
@@ -266,7 +266,7 @@ jobs:
266266

267267
steps:
268268
- name: Checkout repository
269-
uses: actions/checkout@v4.3.1
269+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
270270

271271
- name: Check and validate eclexiaiser manifest
272272
id: eclex
@@ -332,7 +332,7 @@ jobs:
332332

333333
steps:
334334
- name: Checkout repository
335-
uses: actions/checkout@v4.3.1
335+
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
336336

337337
- name: Generate dogfooding scorecard
338338
run: |

‎.github/workflows/generator-generic-ossf-slsa3-publish.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
outputs:
2727
digests: ${{ steps.hash.outputs.digests }}
2828
steps:
29-
- uses: actions/checkout@v4.3.1
29+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
3030
# ========================================================
3131
#
3232
# Step 1: Build your artifacts.

‎.github/workflows/ghcr-publish.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ jobs:
2121
attestations: write # write the build-provenance attestation (the "claim")
2222
steps:
2323
- name: Checkout repository
24-
uses: actions/checkout@v4.1.1
24+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
2525
- name: Install nerdctl and containerd
2626
run: |
2727
sudo apt-get update
@@ -60,7 +60,7 @@ jobs:
6060
# gh attest verify oci://ghcr.io/${{ github.repository }}:<tag> \
6161
# --repo ${{ github.repository }}
6262
- name: Attest container provenance
63-
uses: actions/attest-build-provenance@v2.4.0
63+
uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2.4.0
6464
with:
6565
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
6666
subject-digest: ${{ steps.push.outputs.digest }}

0 commit comments

Comments
 (0)