Commit 86c108b
authored
Pin GitHub Actions to commit SHAs (#600)
Pins GitHub Actions `uses:` references in `github/secure_headers` to
immutable commit SHAs.
## Summary
| Metric | Count |
| --- | ---: |
| Files changed | 3 |
| Files scanned | 2 |
| Refs found | 4 |
| Refs pinned | 4 |
| Skipped refs | 0 |
| Warnings | 1 |
| Errors | 0 |
## Why
Pinning actions to full commit SHAs prevents future tag or branch
retargeting from changing workflow behavior without review.
## Reviewer notes
- Original refs are preserved in inline comments when possible.
- Pin comments use the Dependabot-compatible original-ref style.
- Branch refs were allowed and pinned to their current HEAD; review
mutable-branch pins carefully.
- No minimum action age was enforced for this run.
## Pinned refs
| Location | Before | After | Resolved as |
| --- | --- | --- | --- |
| `.github/workflows/build.yml:16` | `actions/checkout@v7` |
`actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1` | `tag` |
| `.github/workflows/github-release.yml:16` | `actions/checkout@v7` |
`actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1` | `tag` |
| `.github/workflows/github-release.yml:29` |
`actions/create-release@v1` |
`actions/create-release@0cb9c9b65d5d1901c1f53e5e66eaf4afd303e70e` |
`tag` |
| `.github/workflows/github-release.yml:37` | `rubygems/release-gem@v1`
| `rubygems/release-gem@7f9650160c1a4e7989fdc9855807bdbd421d8b6b` |
`branch` |
## Dependabot
- Added a 7-day cooldown (`cooldown: default-days: 7`) to the existing
`github-actions` Dependabot configuration.
- The cooldown delays applying a newly published action release for 7
days, reducing exposure to a compromised or broken release while keeping
you SHA-pinned.
## Warnings
| Location | Ref | Reason |
| --- | --- | --- |
| `.github/workflows/github-release.yml:37` | `rubygems/release-gem@v1`
| pinned mutable branch ref 'v1' to 7f9650160c1a; review carefully
because the source branch can move |
---
Generated by pinner 0.1.0.4 files changed
Lines changed: 8 additions & 7 deletions
File tree
- .github
- workflows
- spec/lib/secure_headers
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
| 8 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | | - | |
| 16 | + | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | | - | |
| 16 | + | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| |||
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | | - | |
| 29 | + | |
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
37 | | - | |
| 37 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
26 | | - | |
27 | | - | |
| 25 | + | |
| 26 | + | |
28 | 27 | | |
29 | 28 | | |
30 | 29 | | |
| |||
0 commit comments