-
-
Notifications
You must be signed in to change notification settings - Fork 0
fix(ci): pin third-party actions to full commit SHAs #76
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Retain the
v0.3.0version annotation.The PR objective requires the original version reference to remain in the trailing comment. Line 43 now contains only the
NOSONARnote and theactions.lockdigest. Add# v0.3.0so the pinned SHA remains traceable to the replaced tag.🤖 Prompt for AI Agents
🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: hyperpolymath/dotmatrix-fileprinter
Length of output: 7186
🏁 Script executed:
Repository: hyperpolymath/dotmatrix-fileprinter
Length of output: 11157
🌐 Web query:
GitHub hyperpolymath smtp-notify-action v0.3.0 22e7bdb322c430c1d0dac6b3bb307f4bb139d0be💡 Result:
<search_synthesis>
The GitHub repository hyperpolymath/smtp-notify-action is a project that provides a Node-free GitHub Action for sending notification emails from workflows [1][2]. The action uses a static Zig-built binary, and its SMTP session is formally specified in Idris2 and machine-checked [3][2]. Regarding the specific version and hash mentioned: - Version v0.3.0 is a released version of the action [3][4]. - The hash 22e7bdb322c430c1d0dac6b3bb307f4bb139d0be appears to be a commit hash associated with the repository&
#39;s history, though it is not the primary pinning method recommended for the action [3]. Users are typically advised to pin actions using SHA-256 hashes (e.g., sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7) to ensure security and reproducibility [3]. The action is designed to support SMTPS (port 465) and STARTTLS (port 587) [1][4]. It serves as a migration path from other email-sending actions and is used in various open-source projects [2]. Documentation for the project includes a KNOWN-DEFECTS.adoc file, which notes that v0.3.0 had issues with STARTTLS binary fetching that were subsequently addressed [5].</search_synthesis>
<source_evidence>
Citations:
Reconcile the workflow pin with
actions.lock. The lockfile recordshyperpolymath/smtp-notify-action@v0.2.0atsha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7, but this workflow runs a different revision. The intended workflow version isv0.3.0, so regenerateactions.lockwithgh actions-lockfor thev0.3.0pin. Do not restore the olderv0.2.0SHA.The mismatch violates the generated lockfile contract. Lock enforcement can reject the workflow before its steps run.
🤖 Prompt for AI Agents