Skip to content

Commit 86c108b

Browse files
authored
Pin GitHub Actions to commit SHAs (#600)
Pins GitHub Actions `uses:` references in `github/secure_headers` to immutable commit SHAs. ## Summary | Metric | Count | | --- | ---: | | Files changed | 3 | | Files scanned | 2 | | Refs found | 4 | | Refs pinned | 4 | | Skipped refs | 0 | | Warnings | 1 | | Errors | 0 | ## Why Pinning actions to full commit SHAs prevents future tag or branch retargeting from changing workflow behavior without review. ## Reviewer notes - Original refs are preserved in inline comments when possible. - Pin comments use the Dependabot-compatible original-ref style. - Branch refs were allowed and pinned to their current HEAD; review mutable-branch pins carefully. - No minimum action age was enforced for this run. ## Pinned refs | Location | Before | After | Resolved as | | --- | --- | --- | --- | | `.github/workflows/build.yml:16` | `actions/checkout@v7` | `actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1` | `tag` | | `.github/workflows/github-release.yml:16` | `actions/checkout@v7` | `actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1` | `tag` | | `.github/workflows/github-release.yml:29` | `actions/create-release@v1` | `actions/create-release@0cb9c9b65d5d1901c1f53e5e66eaf4afd303e70e` | `tag` | | `.github/workflows/github-release.yml:37` | `rubygems/release-gem@v1` | `rubygems/release-gem@7f9650160c1a4e7989fdc9855807bdbd421d8b6b` | `branch` | ## Dependabot - Added a 7-day cooldown (`cooldown: default-days: 7`) to the existing `github-actions` Dependabot configuration. - The cooldown delays applying a newly published action release for 7 days, reducing exposure to a compromised or broken release while keeping you SHA-pinned. ## Warnings | Location | Ref | Reason | | --- | --- | --- | | `.github/workflows/github-release.yml:37` | `rubygems/release-gem@v1` | pinned mutable branch ref 'v1' to 7f9650160c1a; review carefully because the source branch can move | --- Generated by pinner 0.1.0.
2 parents e62871d + 84d9619 commit 86c108b

4 files changed

Lines changed: 8 additions & 7 deletions

File tree

‎.github/dependabot.yml‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,3 +4,5 @@ updates:
44
directory: "/"
55
schedule:
66
interval: "weekly"
7+
cooldown:
8+
default-days: 7

‎.github/workflows/build.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
ruby: [ '2.7', '3.0', '3.1', '3.2', '3.4', '4.0' ]
1414

1515
steps:
16-
- uses: actions/checkout@v7
16+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
1717
- name: Set up Ruby ${{ matrix.ruby }}
1818
uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b #v1.269.0 tag
1919
with:

‎.github/workflows/github-release.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
runs-on: ubuntu-latest
1414
if: startsWith(github.ref, 'refs/tags/v')
1515
steps:
16-
- uses: actions/checkout@v7
16+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
1717
with:
1818
persist-credentials: false
1919
- name: Set up Ruby
@@ -26,12 +26,12 @@ jobs:
2626
RELEASE_NAME=${GITHUB_REF#"refs/tags/"}
2727
echo "RELEASE_NAME=${RELEASE_NAME}" >> $GITHUB_ENV
2828
- name: Publish release
29-
uses: actions/create-release@v1
29+
uses: actions/create-release@0cb9c9b65d5d1901c1f53e5e66eaf4afd303e70e # v1.1.4
3030
env:
3131
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
3232
with:
3333
tag_name: ${{ github.ref }}
3434
release_name: ${{ env.RELEASE_NAME }}
3535
draft: false
3636
prerelease: false
37-
- uses: rubygems/release-gem@v1
37+
- uses: rubygems/release-gem@7f9650160c1a4e7989fdc9855807bdbd421d8b6b # v1.4.1

‎spec/lib/secure_headers/configuration_spec.rb‎

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,9 +22,8 @@ module SecureHeaders
2222
configuration = Configuration.dup
2323
expect(original_configuration).not_to be(configuration)
2424
Configuration::CONFIG_ATTRIBUTES.each do |attr|
25-
# rubocop:disable GitHub/AvoidObjectSendWithDynamicMethod
26-
expect(original_configuration.public_send(attr)).to eq(configuration.public_send(attr))
27-
# rubocop:enable GitHub/AvoidObjectSendWithDynamicMethod
25+
expected_value = original_configuration.instance_variable_get("@#{attr}")
26+
expect(configuration).to have_attributes(attr => expected_value)
2827
end
2928
end
3029

0 commit comments

Comments
 (0)