Skip to content

Pin GitHub Actions to commit SHAs - #164

Merged
elrayle merged 5 commits into
mainfrom
pinner/actions-sha-pins-2026-09-10
Oct 6, 2026
Merged

elrayle merged 5 commits into
mainfrom
pinner/actions-sha-pins-2026-09-10

Conversation

@github-security-bot

@github-security-bot github-security-bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Pins GitHub Actions uses: references in github/go-spdx to immutable commit SHAs.

Summary

Metric Count
Files changed 3
Files scanned 3
Refs found 6
Refs pinned 6
Skipped refs 0
Warnings 1
Errors 0

Why

Pinning actions to full commit SHAs prevents future tag or branch retargeting from changing workflow behavior without review.

Reviewer notes

  • Original refs are preserved in inline comments when possible.
  • Pin comments use the Dependabot-compatible original-ref style.
  • Branch refs were allowed and pinned to their current HEAD; review mutable-branch pins carefully.
  • No minimum action age was enforced for this run.

Pinned refs

Location Before After Resolved as
.github/workflows/fetch-licenses.yaml:27 actions/checkout@v6 actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 tag
.github/workflows/fetch-licenses.yaml:30 actions/checkout@v6 actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 tag
.github/workflows/lint.yaml:16 actions/checkout@v6 actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 tag
.github/workflows/lint.yaml:17 actions/setup-go@v6 actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 tag
.github/workflows/test.yaml:17 actions/checkout@v6 actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 tag
.github/workflows/test.yaml:18 actions/setup-go@v6 actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 tag

Warnings

Location Ref Reason
.github/dependabot.yml `` .github/dependabot.yml left unchanged: github-actions ecosystem present in an unrecognized or complex form

Generated by pinner 0.1.0.

Copilot AI balanced review requested due to automatic review settings September 10, 2026 21:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

All six references use valid full SHAs matching their documented release tags.

Pull request overview

Pins GitHub Actions dependencies to immutable, verified commit SHAs to strengthen workflow supply-chain security.

Changes:

  • Pins actions/checkout to its v6.1.0 commit.
  • Pins actions/setup-go to its v6.5.0 commit.
  • Preserves version references in Dependabot-compatible comments.
File summaries
File Description
.github/workflows/test.yaml Pins test workflow actions.
.github/workflows/lint.yaml Pins lint workflow actions.
.github/workflows/fetch-licenses.yaml Pins both checkout steps.
Review details
  • Files reviewed: 3/3 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@elrayle elrayle left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Versions for checkout and setup-go were advanced by Dependabot since this PR was opened. The SHAs were updated to match those versions before approving this PR.

@elrayle
elrayle merged commit 4a38e14 into main Oct 6, 2026
6 checks passed
@elrayle
elrayle deleted the pinner/actions-sha-pins-2026-09-10 branch October 6, 2026 13:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants