Skip to content

workflows: Pin third-party GitHub Actions to commit hashes - #123

Merged
jtrobles-cdd merged 1 commit into
developfrom
claude/github-actions-pin-hashes-076d76
Sep 14, 2026
Merged

jtrobles-cdd merged 1 commit into
developfrom
claude/github-actions-pin-hashes-076d76

Conversation

@jtrobles-cdd

@jtrobles-cdd jtrobles-cdd commented Sep 14, 2026 •

Copy link
Copy Markdown
Member

Every third-party action used by the workflows of this repository was referenced by a Git tag, which is mutable: the owner of an action can move a tag to different code, and the reference in the workflow does not change. super-linter/super-linter was already pinned to a commit hash; the actions of actions/* were not, and now are.

For the Reviewer

  • The hashes were resolved with gh api repos/<owner>/<repo>/git/ref/tags/<tag>. All three tags are lightweight and point straight at a commit, so there is no annotated tag object to dereference, and each hash can be checked against the corresponding tag on GitHub.
  • The version is kept in a trailing # vX.Y.Z comment, which is the shape super-linter/super-linter already had and the one Dependabot reads and rewrites when it bumps an action, so .github/dependabot.yml needs no change.
  • The calls to the reusable workflows of cordada/github-actions-utils keep their @master reference, because they are internal to the organization and this repository is the one that publishes them.
  • Super-Linter itself was not run before pushing: it runs in a container in continuous integration and this repository provides no task runner target for it, so its verdict here is the one somebody has to read from the checks.

- A Git tag is mutable, so an action referenced by one can be replaced with different code
  without the reference changing, which `super-linter/super-linter` was already pinned against.
- The version each hash corresponds to is kept in a trailing comment, which is the format
  Dependabot reads and rewrites when it bumps the action.
- The reusable workflows of `cordada/github-actions-utils` are left referenced by branch,
  because they are internal to the organization.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@jtrobles-cdd jtrobles-cdd added the dependencies Pull requests or issues about updating dependencies label Sep 14, 2026
@jtrobles-cdd jtrobles-cdd self-assigned this Sep 14, 2026
@sonarqubecloud

Copy link
Copy Markdown

@jtrobles-cdd
jtrobles-cdd merged commit 8ad5ca9 into develop Sep 14, 2026
8 checks passed
@jtrobles-cdd
jtrobles-cdd deleted the claude/github-actions-pin-hashes-076d76 branch September 14, 2026 15:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests or issues about updating dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant