Pin GitHub Actions to commit SHAs and update to latest - #405
Merged
Merged
Conversation
Tag references are mutable and a compromised or hijacked tag could silently pull malicious code into CI, as happened with tj-actions in 2025. Pin every action (including the third-party ones used by the setup-bazelisk composite action) to its full commit SHA with the version as a trailing comment, and bump each to its current latest release: checkout v7.0.1, setup-dotnet v6.0.0, upload-artifact v7.0.1, free-disk-space v2.0.0 (renaming its now-deprecated tool-cache input to preinstalled-runtimes). Also add dependabot.yml so future action releases get picked up as PRs automatically, updating both the SHA and the version comment. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The github-actions ecosystem's directory: "/" entry only scans .github/workflows and a root-level action.yml, so the bazel-contrib/ setup-bazel pin inside .github/actions/setup-bazelisk/action.yml was never being watched for updates. Add a separate entry pointing at that directory. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No unresolved blocking issues were identified in the review.
Review effort: Lite
Findings: None
What changed in this PR
Updates GitHub Actions to current releases, pins them to immutable commit SHAs, and adds Dependabot coverage.
Changes:
- Updates and pins workflow and composite actions.
- Renames the deprecated disk-space input.
- Adds weekly Dependabot updates.
| File | Description |
|---|---|
.github/workflows/deploy_pages.yml |
Pins deployment dependencies. |
.github/workflows/ci_windows.yml |
Pins Windows CI actions. |
.github/workflows/ci_windows_dotnet.yml |
Pins .NET workflow actions. |
.github/workflows/ci_wasm.yml |
Pins WASM CI actions and updates disk cleanup. |
.github/workflows/ci_macos.yml |
Pins macOS CI actions. |
.github/workflows/ci_linux.yml |
Pins and updates Linux CI actions. |
.github/dependabot.yml |
Adds weekly action dependency monitoring. |
.github/actions/setup-bazelisk/action.yml |
Pins Bazel setup dependencies. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
tameware
approved these changes
Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
uses:reference (workflow actions and the third-party action inside thesetup-bazeliskcomposite action) to its full commit SHA, with the version kept as a trailing comment, to close the supply-chain risk of a mutable tag being repointed at malicious code.actions/checkoutv7.0.1,actions/setup-dotnetv6.0.0,actions/upload-artifactv7.0.1,jlumbroso/free-disk-spacev2.0.0 (renaming its now-deprecatedtool-cacheinput topreinstalled-runtimes);actions/upload-pages-artifact,actions/deploy-pages, andbazel-contrib/setup-bazelwere already at their latest..github/dependabot.ymlso future action releases are picked up automatically as PRs, with a separate entry for thesetup-bazeliskcomposite action directory since Dependabot'sgithub-actionsecosystem doesn't recurse into composite actions outside.github/workflows.Test plan
Closes #322