Skip to content

Commit 37ce0f2

Browse files
committed
fix(ci): pin third-party actions to full commit SHAs
The account's Actions policy requires a full-length SHA ref. A tag or branch ref is refused at startup — `startup_failure`, no jobs, "this workflow graph cannot be shown" — so these workflows could not run at all. This resolves each ref to the commit it currently points at and records the ref in a trailing comment, e.g. `actions/checkout@<sha> # v4`. `dtolnay/rust-toolchain` takes its toolchain from the ref itself, so those steps also gained an explicit `with: toolchain:` input; without it, a SHA ref would silently lose the channel. No behaviour is intended to change beyond the pins.
1 parent b095fa4 commit 37ce0f2

10 files changed

Lines changed: 35 additions & 35 deletions

‎.github/workflows/abi-ffi-gate.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ jobs:
2121
name: ABI ↔ FFI structural conformance
2222
runs-on: ubuntu-latest
2323
steps:
24-
- uses: actions/checkout@v7.0.1
24+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2525
- name: Install Julia 1.11.5
2626
run: |
2727
curl --proto "=https" --proto-redir "=https" --tlsv1.2 -fsSL https://julialang-s3.julialang.org/bin/linux/x64/1.11/julia-1.11.5-linux-x86_64.tar.gz -o /tmp/julia.tar.gz
@@ -39,7 +39,7 @@ jobs:
3939
name: Zig FFI builds + tests (Zig 0.14.0)
4040
runs-on: ubuntu-latest
4141
steps:
42-
- uses: actions/checkout@v7.0.1
42+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
4343
- name: Install Zig 0.14.0
4444
run: |
4545
curl --proto "=https" --proto-redir "=https" --tlsv1.2 -fsSL https://ziglang.org/download/0.14.0/zig-linux-x86_64-0.14.0.tar.xz -o /tmp/zig.tar.xz

‎.github/workflows/boj-build.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ jobs:
1111
runs-on: ubuntu-latest
1212
steps:
1313
- name: Checkout
14-
uses: actions/checkout@v7.0.1
14+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
1515
- name: Trigger BoJ Server (Casket/ssg-mcp)
1616
run: |
1717
# Send a secure trigger to boj-server to build this repository

‎.github/workflows/casket-pages.yml‎

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -22,22 +22,22 @@ jobs:
2222
runs-on: ubuntu-latest
2323
steps:
2424
- name: Checkout
25-
uses: actions/checkout@v7.0.1
25+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2626

2727
- name: Checkout casket-ssg
28-
uses: actions/checkout@v7.0.1
28+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2929
with:
3030
repository: hyperpolymath/casket-ssg
3131
path: .casket-ssg
3232

3333
- name: Setup GHCup
34-
uses: haskell-actions/setup@v2.12.0
34+
uses: haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d # v2.12.0
3535
with:
3636
ghc-version: '9.8.2'
3737
cabal-version: '3.10'
3838

3939
- name: Cache Cabal
40-
uses: actions/cache@v6.1.0
40+
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
4141
with:
4242
path: |
4343
~/.cabal/packages
@@ -99,10 +99,10 @@ jobs:
9999
touch ../_site/.nojekyll
100100
101101
- name: Setup Pages
102-
uses: actions/configure-pages@v6.0.0
102+
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
103103

104104
- name: Upload artifact
105-
uses: actions/upload-pages-artifact@v5.0.0
105+
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
106106
with:
107107
path: '_site'
108108

@@ -115,4 +115,4 @@ jobs:
115115
steps:
116116
- name: Deploy to GitHub Pages
117117
id: deployment
118-
uses: actions/deploy-pages@v5.0.1
118+
uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1

‎.github/workflows/codeql.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -37,15 +37,15 @@ jobs:
3737

3838
steps:
3939
- name: Checkout
40-
uses: actions/checkout@v7.0.1
40+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
4141

4242
- name: Initialize CodeQL
43-
uses: github/codeql-action/init@v4.38.0
43+
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
4444
with:
4545
languages: ${{ matrix.language }}
4646
build-mode: ${{ matrix.build-mode }}
4747

4848
- name: Perform CodeQL Analysis
49-
uses: github/codeql-action/analyze@v4.38.0
49+
uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
5050
with:
5151
category: "/language:${{ matrix.language }}"

‎.github/workflows/dogfood-gate.yml‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727

2828
steps:
2929
- name: Checkout repository
30-
uses: actions/checkout@v7.0.1
30+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
3131

3232
- name: Check for A2ML files
3333
id: detect
@@ -67,7 +67,7 @@ jobs:
6767

6868
steps:
6969
- name: Checkout repository
70-
uses: actions/checkout@v7.0.1
70+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
7171

7272
- name: Check for K9 files
7373
id: detect
@@ -112,7 +112,7 @@ jobs:
112112

113113
steps:
114114
- name: Checkout repository
115-
uses: actions/checkout@v7.0.1
115+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
116116

117117
- name: Scan for invisible characters
118118
id: lint
@@ -176,7 +176,7 @@ jobs:
176176

177177
steps:
178178
- name: Checkout repository
179-
uses: actions/checkout@v7.0.1
179+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
180180

181181
- name: Check for Groove manifest
182182
id: groove
@@ -234,7 +234,7 @@ jobs:
234234

235235
steps:
236236
- name: Checkout repository
237-
uses: actions/checkout@v7.0.1
237+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
238238

239239
- name: Check and validate eclexiaiser manifest
240240
id: eclex
@@ -299,7 +299,7 @@ jobs:
299299

300300
steps:
301301
- name: Checkout repository
302-
uses: actions/checkout@v7.0.1
302+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
303303

304304
- name: Generate dogfooding scorecard
305305
run: |

‎.github/workflows/instant-sync.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ jobs:
2222
- name: Trigger Propagation
2323
id: propagate
2424
if: env.FARM_DISPATCH_TOKEN != ''
25-
uses: peter-evans/repository-dispatch@v4.0.1
25+
uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v4.0.1
2626
with:
2727
token: ${{ secrets.FARM_DISPATCH_TOKEN }}
2828
repository: hyperpolymath/.git-private-farm

‎.github/workflows/push-email-notify.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ jobs:
4040
timeout-minutes: 5
4141
steps:
4242
- name: Send push notification email
43-
uses: hyperpolymath/smtp-notify-action@v0.3.0 # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7)
43+
uses: hyperpolymath/smtp-notify-action@22e7bdb322c430c1d0dac6b3bb307f4bb139d0be # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7)
4444
with:
4545
server_address: ${{ secrets.SMTP_HOST }}
4646
server_port: ${{ secrets.SMTP_PORT }}

‎.github/workflows/release.yml‎

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ jobs:
2323
permissions:
2424
contents: read
2525
steps:
26-
- uses: actions/checkout@v7.0.1
26+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2727

2828
- name: Build
2929
run: |
@@ -50,7 +50,7 @@ jobs:
5050
changelog: ${{ steps.cliff.outputs.content }}
5151
version: ${{ steps.version.outputs.version }}
5252
steps:
53-
- uses: actions/checkout@v7.0.1
53+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
5454
with:
5555
fetch-depth: 0
5656

@@ -80,7 +80,7 @@ jobs:
8080
git cliff --output CHANGELOG.md
8181
8282
- name: Upload updated CHANGELOG.md
83-
uses: actions/upload-artifact@v7.0.1
83+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
8484
with:
8585
name: changelog
8686
path: CHANGELOG.md
@@ -93,7 +93,7 @@ jobs:
9393
permissions:
9494
contents: write
9595
steps:
96-
- uses: actions/checkout@v7.0.1
96+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
9797

9898
# TODO: Download build artifacts if uploading to the release
9999
# - uses: actions/download-artifact@v4
@@ -102,7 +102,7 @@ jobs:
102102
# path: artifacts/
103103

104104
- name: Create GitHub Release
105-
uses: softprops/action-gh-release@v3.0.3
105+
uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3
106106
with:
107107
body: ${{ needs.changelog.outputs.changelog }}
108108
draft: false

‎.github/workflows/rhodibot.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ jobs:
3434
timeout-minutes: 15
3535
steps:
3636
- name: Checkout
37-
uses: actions/checkout@v7.0.1
37+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
3838
with:
3939
fetch-depth: 1
4040
- name: Rhodibot — detect drift (no mutations)

‎.github/workflows/static-analysis-gate.yml‎

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ jobs:
2424

2525
steps:
2626
- name: Checkout repository
27-
uses: actions/checkout@v7.0.1
27+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2828
with:
2929
fetch-depth: 0
3030

@@ -127,7 +127,7 @@ jobs:
127127
echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY"
128128
129129
- name: Upload panic-attack findings
130-
uses: actions/upload-artifact@v7.0.1
130+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
131131
with:
132132
name: panic-attack-findings
133133
path: panic-attack-findings.json
@@ -148,14 +148,14 @@ jobs:
148148

149149
steps:
150150
- name: Checkout repository
151-
uses: actions/checkout@v7.0.1
151+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
152152
with:
153153
fetch-depth: 0
154154

155155
- name: Setup Elixir for Hypatia scanner
156156
id: beam
157157
continue-on-error: true
158-
uses: erlef/setup-beam@v1.24.1
158+
uses: erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124 # v1.24.1
159159
with:
160160
elixir-version: '1.19.4'
161161
otp-version: '28.3'
@@ -261,7 +261,7 @@ jobs:
261261
echo "Skipped: Hypatia scanner not available in this environment." >> "$GITHUB_STEP_SUMMARY"
262262
263263
- name: Upload hypatia findings
264-
uses: actions/upload-artifact@v7.0.1
264+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
265265
with:
266266
name: hypatia-findings
267267
path: hypatia-findings.json
@@ -284,13 +284,13 @@ jobs:
284284

285285
steps:
286286
- name: Download panic-attack findings
287-
uses: actions/download-artifact@v8.0.1
287+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
288288
with:
289289
name: panic-attack-findings
290290
path: findings/
291291

292292
- name: Download hypatia findings
293-
uses: actions/download-artifact@v8.0.1
293+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
294294
with:
295295
name: hypatia-findings
296296
path: findings/
@@ -344,7 +344,7 @@ jobs:
344344
echo "low=$LOW" >> "$GITHUB_OUTPUT"
345345
346346
- name: Upload unified findings (fleet scanner picks these up)
347-
uses: actions/upload-artifact@v7.0.1
347+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
348348
with:
349349
name: unified-findings
350350
path: findings/unified-findings.json

0 commit comments

Comments
 (0)