Skip to content

chore(ci): pin third-party GitHub Actions to commit SHAs - #137

Merged
zacharybalicki merged 2 commits into
mainfrom
chore/ghx-action-sha-pinning-2026-09-29
Sep 29, 2026
Merged

zacharybalicki merged 2 commits into
mainfrom
chore/ghx-action-sha-pinning-2026-09-29

Conversation

@zacharybalicki

@zacharybalicki zacharybalicki commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Pins floating third-party uses: refs in .github/workflows/ to the commit SHAs in ACTION-SHA-PINNING-PR-SPEC (2026-09-29). Inventory before the pin commit: tag-pinned dominant, any_sha_pinned_third_party: false.

w3-lab-teardown-verify.yml is pin-only (checkout, aws-actions, upload-artifact). This does not rewrite teardown or OIDC logic. AWS account IDs, role ARNs, regions, and environment names are unchanged. This does not publish and does not dispatch publish or teardown.

./.github/actions/vantio-prove stays on floating @v4.

Pin map:

  • actions/checkout@v4 → 11d5960a326750d5838078e36cf38b85af677262 # v4
  • actions/setup-node@v4 → 49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
  • actions/setup-python@v5 → a26af69be951a213d495a4c3e4e4022e16d87065 # v5
  • pnpm/action-setup@v4 → b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4
  • actions/upload-artifact@v4 → ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
  • actions/attest-build-provenance@v2 → e8998f949152b193b063cb0ec769d69d929409be # v2
  • aws-actions/configure-aws-credentials@v6 → e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6
  • pypa/gh-action-pypi-publish@release/v1 → dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1

Each listed SHA resolved on GitHub and matches the peeled tag or the recorded release/v1 commit. No newer SHA was substituted.

Follow-up on the same branch: release-governance contracts were still locking the floating tags, so a pin-only merge would turn the Release governance contract job red. This commit keeps the pin map and updates only those locks:

  • scripts/aws/test_w3_lab_teardown_workflow.py and scripts/release/test_pypi_publish_workflow.py expect the SHA plus the tag comment. Role ARN, account id, region, environment, and permissions are unchanged.
  • scripts/release/ws11/inventory.mjs keeps uses: lines written as owner/name@sha # tag, including a leading - uses: marker. Those rows are digest_pinned: true. The local composite action stays unpinned.
  • Generated pin-report.json, the Optics dossier, and evaluations.json were emitted from that scanner. 00-INVENTORY.md now matches the report.
Open in Web Open in Cursor 

Replace floating third-party uses refs with the 2026-09-29 pin map
and keep the tag comments. w3-lab-teardown-verify.yml is pin-only.
The local vantio-prove action is unchanged.
The pin commit records third-party uses lines as owner/name@sha # tag.
Workflow contract tests and the WS11 pin report still required floating
tags, and the scanner dropped uses lines that carried a tag comment.
@zacharybalicki
zacharybalicki merged commit e44d0cf into main Sep 29, 2026
8 checks passed
zacharybalicki added a commit that referenced this pull request Sep 29, 2026
Pin setup-node and upload-artifact inside the local vantio-prove composite to the #137 SHA map with # v4 comments. Regenerate the WS11 pin report so those two uses are digest_pinned.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant