Repository navigation
Emit parseable version comments for SHA-pinned actions - #66671
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
There was a problem hiding this comment.
🟡 Changes recommended
Unresolved mapping failures, provenance loss, incorrect metadata fetching, and unverified version labels can produce incorrect workflows.
4 open findings
What changed in this PR
Updates gh-aw’s action pinning to emit version comments that zizmor can parse, addressing #66423.
Changes:
- Replaces parenthetical version metadata with a single version token.
- Applies exact action mappings before prefix rewriting.
- Updates tests for version selection and fallback comments.
| File | Description |
|---|---|
| pkg/workflow/action_pins.go | Applies early exact mappings and marks their targets. |
| pkg/workflow/action_pins_test.go | Updates fallback comment expectations. |
| pkg/actionpins/spec_test.go | Tests single-token comments and exact source tags. |
| pkg/actionpins/resolve.go | Uses resolved versions for fallback comments. |
| pkg/actionpins/references.go | Selects a single version label. |
| pkg/actionpins/actionpins_internal_test.go | Covers version-label selection. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
| if ctx != nil { | ||
| if _, mapped := data.ActionPinMappings[actionpins.FormatCacheKey(actionRepo, version)]; mapped { | ||
| ctx.GHES = false | ||
| ctx.Mappings = data.ActionPinMappings |
There was a problem hiding this comment.
Fixed in d46d356: action metadata lookup and caching now use the mapped target repository, subdirectory, and ref.
| exactMapped = true | ||
| } | ||
| } | ||
| ref, err := actionpins.ResolveActionPin(actionRepo, version, ctx) |
There was a problem hiding this comment.
Fixed in d46d356: invalid or unresolved exact mappings now return errors, and safe-output, typed-step, and generated-action callers no longer silently retain the source action.
| } | ||
| actionPinsLog.Printf("Version resolved: source=%s resolved=%s for repo=%s", sourceVersion, resolvedVersion, repo) | ||
| return FormatPinnedActionReference(repo, sha, resolvedVersion+" (source "+sourceVersion+")") | ||
| if semverutil.IsActionVersionTag(sourceVersion) && strings.HasPrefix(sourceVersion, resolvedVersion+".") { |
There was a problem hiding this comment.
Fixed in d46d356: source-version preference is limited to precise vN.N.N release tags; partial minor tags use the resolved version.
| if !strings.Contains(ref, " # ") { | ||
| ref += " #" | ||
| } | ||
| ref += exactPinMappingMarker |
There was a problem hiding this comment.
Fixed in d46d356: mapping provenance is now carried on each step’s name through YAML transformations, rather than relying on shared comment metadata. Added a regression for sanitization and identical mapped/ordinary refs.
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: 3cfb63e
|
…-comments-version Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: d46d356
|
…-comments-version Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
🎉 This pull request is included in a new release. Release: |


Recompilation could emit comments such as
# v9 (source v9.0.0). Zizmor cannot parse a version from that format and flags otherwise valid SHA pins.