The actionlint workflow downloads its executable by running the script at https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash in .github/workflows/actionlint.yml.
The URL follows the mutable main branch, so an unchanged commit can run a different checker after an upstream change and an old failure cannot be reproduced from the workflow file.
Expected result:
Pin the downloader to a versioned actionlint release or commit, and update that reference explicitly when the project chooses a new version.
The actionlint workflow downloads its executable by running the script at
https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bashin.github/workflows/actionlint.yml.The URL follows the mutable
mainbranch, so an unchanged commit can run a different checker after an upstream change and an old failure cannot be reproduced from the workflow file.Expected result:
Pin the downloader to a versioned actionlint release or commit, and update that reference explicitly when the project chooses a new version.