Skip to content

Pin GitHub Actions to commit SHAs and update to latest - #405

Merged
zzcgumn merged 2 commits into
developfrom
chore/update_github_actions
Sep 27, 2026
Merged

zzcgumn merged 2 commits into
developfrom
chore/update_github_actions

Conversation

@zzcgumn

@zzcgumn zzcgumn commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Pin every uses: reference (workflow actions and the third-party action inside the setup-bazelisk composite action) to its full commit SHA, with the version kept as a trailing comment, to close the supply-chain risk of a mutable tag being repointed at malicious code.
  • Bump each action to its current latest release: actions/checkout v7.0.1, actions/setup-dotnet v6.0.0, actions/upload-artifact v7.0.1, jlumbroso/free-disk-space v2.0.0 (renaming its now-deprecated tool-cache input to preinstalled-runtimes); actions/upload-pages-artifact, actions/deploy-pages, and bazel-contrib/setup-bazel were already at their latest.
  • Add .github/dependabot.yml so future action releases are picked up automatically as PRs, with a separate entry for the setup-bazelisk composite action directory since Dependabot's github-actions ecosystem doesn't recurse into composite actions outside .github/workflows.

Test plan

  • CI runs green on this PR across all workflows (linux/macos/windows/wasm/dotnet/pages)

Closes #322

zzcgumn and others added 2 commits September 27, 2026 14:30
Tag references are mutable and a compromised or hijacked tag could
silently pull malicious code into CI, as happened with tj-actions in
2025. Pin every action (including the third-party ones used by the
setup-bazelisk composite action) to its full commit SHA with the
version as a trailing comment, and bump each to its current latest
release: checkout v7.0.1, setup-dotnet v6.0.0, upload-artifact v7.0.1,
free-disk-space v2.0.0 (renaming its now-deprecated tool-cache input
to preinstalled-runtimes).

Also add dependabot.yml so future action releases get picked up as
PRs automatically, updating both the SHA and the version comment.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The github-actions ecosystem's directory: "/" entry only scans
.github/workflows and a root-level action.yml, so the bazel-contrib/
setup-bazel pin inside .github/actions/setup-bazelisk/action.yml was
never being watched for updates. Add a separate entry pointing at
that directory.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified in the review.

Review effort: Lite
Findings: None

What changed in this PR

Updates GitHub Actions to current releases, pins them to immutable commit SHAs, and adds Dependabot coverage.

Changes:

  • Updates and pins workflow and composite actions.
  • Renames the deprecated disk-space input.
  • Adds weekly Dependabot updates.
File Description
.github/​workflows/​deploy_pages.yml Pins deployment dependencies.
.github/​workflows/​ci_windows.yml Pins Windows CI actions.
.github/​workflows/​ci_windows_dotnet.yml Pins .NET workflow actions.
.github/​workflows/​ci_wasm.yml Pins WASM CI actions and updates disk cleanup.
.github/​workflows/​ci_macos.yml Pins macOS CI actions.
.github/​workflows/​ci_linux.yml Pins and updates Linux CI actions.
.github/​dependabot.yml Adds weekly action dependency monitoring.
.github/​actions/​setup-bazelisk/​action.yml Pins Bazel setup dependencies.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@zzcgumn
zzcgumn merged commit d428c94 into develop Sep 27, 2026
14 checks passed
@zzcgumn
zzcgumn deleted the chore/update_github_actions branch September 27, 2026 17:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update all GitHub actions to their latest versions.

3 participants