Skip to content

Pin GitHub Actions to commit hashes - #3020

Merged
pocke merged 1 commit into
ruby:masterfrom
pocke:Pin_GitHub_Actions_to_commit_hashes
Aug 10, 2026
Merged

Pin GitHub Actions to commit hashes#3020
pocke merged 1 commit into
ruby:masterfrom
pocke:Pin_GitHub_Actions_to_commit_hashes

Conversation

@pocke

@pocke pocke commented Jun 29, 2026

Copy link
Copy Markdown
Member

Run pinact to replace mutable tag references (e.g. actions/checkout@v7) with their corresponding full commit SHAs, keeping the version tag as a trailing comment. Pinning to immutable SHAs prevents a compromised or retagged action from silently changing behavior in CI.

Generated with: pinact run (pinact v4.1.0)

Run pinact to replace mutable references (e.g. actions/checkout@v7,
ruby/setup-ruby@v1) with the full commit SHA of the release they
currently resolve to, keeping the version as a trailing comment.

Pinning to immutable SHAs prevents a compromised or retagged action from
silently changing what CI executes. Every action in .github/workflows/
is covered; the resulting versions are:

  actions/checkout                          v7.0.1
  actions/cache                             v6.1.0
  actions/upload-artifact                   v7.0.1
  ruby/setup-ruby                           v1.321.0
  rubygems/configure-rubygems-credentials   v2.1.0
  bytecodealliance/actions                  v1.1.3

dependabot/fetch-metadata was already pinned and is left untouched.

The note above rubygems/configure-rubygems-credentials explaining why it
alone used an exact release is dropped: every action carries an exact
version now, so the contrast it pointed at no longer exists.

Dependabot understands the "SHA # version" form and rewrites both parts,
so .github/dependabot.yml keeps working as the update path. Note this
makes ruby/setup-ruby lag behind its releases, which mostly exist to add
newly released Ruby versions to its build matrix; a workflow pinned to an
exact ruby-version can fail until Dependabot catches up, and one asking
for a series such as "4.0" silently stays on an older patch.

Generated with: pinact run (pinact v4.1.1)
https://github.com/suzuki-shunsuke/pinact

ハッシュ固め夜半の月さえ動かさず
@pocke
pocke force-pushed the Pin_GitHub_Actions_to_commit_hashes branch from 53496a9 to 650f89b Compare August 10, 2026 05:21
@pocke
pocke added this pull request to the merge queue Aug 10, 2026
Merged via the queue into ruby:master with commit 76d8c7d Aug 10, 2026
31 checks passed
@pocke
pocke deleted the Pin_GitHub_Actions_to_commit_hashes branch August 10, 2026 06:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants