Repository navigation
fix(ci): pin third-party actions to full commit SHAs #394
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,3 +1,3 @@ | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
| # Rust CI — thin wrapper calling the shared estate reusable in | ||
|
|
@@ -45,15 +45,17 @@ | |
| # for the in-tree codec that makes this possible. | ||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v7.0.1 | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
|
|
||
| - name: Install Rust toolchain | ||
| uses: dtolnay/rust-toolchain@v1 | ||
| uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 | ||
| with: | ||
| toolchain: v1 | ||
|
Comment on lines
+52
to
+53
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🔴 Critical | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: sed -n '40,70p' .github/workflows/rust-ci.yml
echo ---
sed -n '85,105p' .github/workflows/rust-ci.yml
echo ---
sed -n '35,75p' .github/workflows/status-gate.ymlRepository: hyperpolymath/ephapax Length of output: 4184 Keep one Rust toolchain input per step. Both install steps define
🤖 Prompt for AI Agents |
||
| with: | ||
| toolchain: stable # required when SHA-pinned (no rust-toolchain.toml in repo) | ||
|
|
||
| - name: Cache cargo registry and build | ||
| uses: Swatinem/rust-cache@v2.9.2 | ||
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | ||
| with: | ||
| key: no-default-features | ||
|
|
||
|
|
@@ -87,15 +89,15 @@ | |
| # known rustc-incremental ICE on ephapax-parser. | ||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v7.0.1 | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
|
|
||
| - name: Install Rust toolchain | ||
| uses: dtolnay/rust-toolchain@v1 | ||
| uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 | ||
| with: | ||
| toolchain: stable # required when SHA-pinned (no rust-toolchain.toml in repo) | ||
|
|
||
| - name: Cache cargo registry and build | ||
| uses: Swatinem/rust-cache@v2.9.2 | ||
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | ||
| with: | ||
| key: wasm-validate | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: hyperpolymath/ephapax
Length of output: 3521
🤖 get_repo_knowledge executed:
get_repo_knowledge hyperpolymath/ephapax /tmp/coderabbit-repo-knowledge/hyperpolymath-ephapax-19a79923Length of output: 966
🏁 Script executed:
Repository: hyperpolymath/ephapax
Length of output: 8792
Regenerate
actions.lockfor the pinned Rust toolchain.Both workflows use
dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de, butactions.lockrecordsv1and resolves it to6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772. Regenerate the lock file so both workflow entries and the dependency record match the pinned SHA.📍 Affects 2 files
.github/workflows/rust-ci.yml#L51-L53(this comment).github/workflows/status-gate.yml#L62-L64🤖 Prompt for AI Agents