Skip to content

Emit parseable version comments for SHA-pinned actions - #66671

Merged
pelikhan merged 7 commits into
mainfrom
copilot/fix-v0914-pin-comments-version
Oct 7, 2026
Merged

pelikhan merged 7 commits into
mainfrom
copilot/fix-v0914-pin-comments-version

Conversation

Copilot AI commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Recompilation could emit comments such as # v9 (source v9.0.0). Zizmor cannot parse a version from that format and flags otherwise valid SHA pins.

  • Pin comments: Emit one version token. Prefer a verified exact source tag when it refines the resolved tag; otherwise use the version of the pinned SHA.
    uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
  • Mapping precedence: Apply exact action mappings while the requested tag is available, without letting the later prefix rewrite alter their targets. Continue accepting older parenthetical comments as mapping input.

Copilot AI and others added 2 commits October 7, 2026 19:58
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix pin comments version mismatch in actions/github-script Emit parseable version comments for SHA-pinned actions Oct 7, 2026
Copilot AI requested a review from pelikhan October 7, 2026 20:13
@pelikhan
pelikhan marked this pull request as ready for review October 7, 2026 20:15
Copilot AI balanced review requested due to automatic review settings October 7, 2026 20:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved mapping failures, provenance loss, incorrect metadata fetching, and unverified version labels can produce incorrect workflows.

4 open findings
What changed in this PR

Updates gh-aw’s action pinning to emit version comments that zizmor can parse, addressing #66423.

Changes:

  • Replaces parenthetical version metadata with a single version token.
  • Applies exact action mappings before prefix rewriting.
  • Updates tests for version selection and fallback comments.
File Description
pkg/​workflow/​action_pins.go Applies early exact mappings and marks their targets.
pkg/​workflow/​action_pins_test.go Updates fallback comment expectations.
pkg/​actionpins/​spec_test.go Tests single-token comments and exact source tags.
pkg/​actionpins/​resolve.go Uses resolved versions for fallback comments.
pkg/​actionpins/​references.go Selects a single version label.
pkg/​actionpins/​actionpins_internal_test.go Covers version-label selection.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

if ctx != nil {
if _, mapped := data.ActionPinMappings[actionpins.FormatCacheKey(actionRepo, version)]; mapped {
ctx.GHES = false
ctx.Mappings = data.ActionPinMappings

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in d46d356: action metadata lookup and caching now use the mapped target repository, subdirectory, and ref.

exactMapped = true
}
}
ref, err := actionpins.ResolveActionPin(actionRepo, version, ctx)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in d46d356: invalid or unresolved exact mappings now return errors, and safe-output, typed-step, and generated-action callers no longer silently retain the source action.

Comment thread pkg/actionpins/references.go Outdated
}
actionPinsLog.Printf("Version resolved: source=%s resolved=%s for repo=%s", sourceVersion, resolvedVersion, repo)
return FormatPinnedActionReference(repo, sha, resolvedVersion+" (source "+sourceVersion+")")
if semverutil.IsActionVersionTag(sourceVersion) && strings.HasPrefix(sourceVersion, resolvedVersion+".") {

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in d46d356: source-version preference is limited to precise vN.N.N release tags; partial minor tags use the resolved version.

Comment thread pkg/workflow/action_pins.go Outdated
if !strings.Contains(ref, " # ") {
ref += " #"
}
ref += exactPinMappingMarker

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in d46d356: mapping provenance is now carried on each step’s name through YAML transformations, rather than relying on shared comment metadata. Added a regression for sanitization and identical mapped/ordinary refs.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Review (pkg/workflow/action_pins.go:314): Early exact mapping changes the repository and SHA returned to fetchAndParseActionYAML, but that caller still fetches action.yml from the original repository/subdirectory (safe_outputs_actions.go:231). With no cached or explicit inputs, a replacement-only commit is fetched from the wrong repository, metadata retrieval fails, and the generated step receives a generic payload input instead of the action's declared inputs. Fetch and cache metadata using the resolved target repository, subdirectory, and ref. - Emit parseable version comments for SHA-pinned actions #66671 (comment)
  3. Review (pkg/workflow/action_pins.go:318): An unresolved exact mapping can now silently emit the original action. For example, if actions/github-script@v9 maps to an unavailable internal/script@v1, resolution returns an error or an empty reference. applyActionPinToTypedStep discards either result and keeps actions/github-script@v9. The final mapping pass only matches SHA-pinned lines, so it skips this step and compilation can succeed without the configured redirect. Previously that pass rejected an unresolved target after pinning the source. Treat empty mapped results as failures and propagate mapped-target failures through callers instead of retaining the source reference. - Emit parseable version comments for SHA-pinned actions #66671 (comment)
  4. Review (pkg/actionpins/references.go:41): This condition also prefers unverified minor tags, not just exact release tags. lookupEmbeddedActionPin treats v9.999 as non-precise and checks only major-version compatibility, so it can return the embedded v9 SHA without resolving the requested tag. This then emits # v9.999, even if that tag does not exist, recreating a ref/version mismatch. Restrict source preference to precise release tags; otherwise keep the resolved version. - Emit parseable version comments for SHA-pinned actions #66671 (comment)
  5. Review (pkg/workflow/action_pins.go:323): The comment marker does not reliably preserve per-step exact-mapping precedence. sanitizeCustomStepsYAML drops comments when it rewrites a sibling run step containing an expression such as ${{ github.event.issue.title }}. Also, proxy injection and runtime deduplication preserve comments in maps keyed only by repo@SHA, so an exact-mapped step and an ordinary step resolving to the same reference overwrite each other's marker. The final pass can then prefix-rewrite an exact target or incorrectly exempt an ordinary step. Preserve mapping provenance per step through all these transformations, rather than relying on shared or discarded YAML comments. - Emit parseable version comments for SHA-pinned actions #66671 (comment)

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: 3cfb63e
Sous-chef work: 063f32df9b0cdade3e04b458f78b45a649ff6aaf48fe5f8cb9a248aba2a84358 58c88e5353f38c2dc915df058033c1f2ca4922a9a6666d9f206bb3943771ab79 d820501069d424730f5d90da10b774535957f27e3b4c78b4d10048dafd297ec7 dd867e147b305c1fb9a7b41ee8b6833c1a5516a726e6f2fb27a33c2f78f84238
Sous-chef state: e4b65dd7cc07c66a579bdb7cb1d6eafed8963be418c87075b494503e2f911400

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 5.6 AIC · ⌖ 10.7 AIC · ⊞ 1K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits October 7, 2026 20:51
…-comments-version

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Copilot AI requested a review from gh-aw-bot October 7, 2026 21:34
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Fix failing check build-wasm (FAILURE): https://github.com/github/gh-aw/actions/runs/37689797684/job/113042470544.
  3. Fix failing check impacted-go-tests (FAILURE): https://github.com/github/gh-aw/actions/runs/37689797684/job/113042470031.

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: d46d356
Sous-chef work: 42e5d572d9d75b7168fe7d0aeda0717cc07e65ed240f6d299e6fec661214f1ac 8acb61a077717e3a460018aacdfde96fd489f77606cd36169e2328d9079b75bb
Sous-chef state: 1a687cba1865f01056c5b137ea68b25030687358db2a6f09a019a1a4ac46a41d

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 2.81 AIC · ⌖ 7.94 AIC · ⊞ 1K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits October 7, 2026 22:33
…-comments-version

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
@pelikhan
pelikhan merged commit bad24e3 into main Oct 7, 2026
2 checks passed
@pelikhan
pelikhan deleted the copilot/fix-v0914-pin-comments-version branch October 7, 2026 23:09
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

v0.91.4 pin comments "# v9 (source v9.0.0)" fail zizmor ref-version-mismatch

4 participants