DEVOPS-1133: Pin GitHub Actions to commit hashes - #85
Conversation
There was a problem hiding this comment.
Pull request overview
This PR updates GitHub Actions reusable workflow references to a more specific MiraGeoscience/CI-tools release tag (v3.9.1) as part of an effort to harden workflow supply-chain integrity.
Changes:
- Updated multiple
.github/workflows/*.ymlreusable-workflowuses:references from@v3to@v3.9.1. - Standardized the referenced CI-tools version across security scanning, Python analysis, deployment, and JIRA automation workflows.
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 7 comments.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/security_scan.yml | Updates CI-tools Zizmor reusable workflow references to v3.9.1. |
| .github/workflows/python_deploy_prod.yml | Updates production release reusable workflows to v3.9.1. |
| .github/workflows/python_deploy_dev.yml | Updates development publish reusable workflows to v3.9.1. |
| .github/workflows/python_analysis.yml | Updates static analysis and pytest reusable workflows to v3.9.1. |
| .github/workflows/pr_jira_actions.yml | Updates PR→JIRA reusable workflow reference to v3.9.1. |
| .github/workflows/issue_to_jira.yml | Updates issue→JIRA reusable workflow reference to v3.9.1. |
Comments suppressed due to low confidence (3)
.github/workflows/python_deploy_prod.yml:45
- This reusable workflow is referenced by tag (
v3.9.1). Pin to the commit SHA (with a version comment) so the workflow reference is immutable.
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_pypi_assets.yml@v3.9.1
.github/workflows/python_deploy_dev.yml:33
- This reusable workflow is referenced by tag (
v3.9.1). Pin to the exact commit SHA (with a version comment) to make the reference immutable.
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_pypi_package.yml@v3.9.1
.github/workflows/python_analysis.yml:39
- This reusable workflow is referenced by tag (
v3.9.1). Pin to the commit SHA (with a version comment) to prevent tag retargeting.
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-pytest.yml@v3.9.1
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
c30031e to
9b1b5f6
Compare
|
|
Pin all GitHub Actions and reusable workflow references to immutable commit hashes, and add the dependabot auto-merge and WIP status workflows.
0bd5a95 to
749ce5f
Compare
|
|
DEVOPS-1133 - pin all GitHub actions and reusable workflows to hash
Expands moving GitHub Actions tags to the full semver tag pointing at the same commit, then pins every
uses:to a commit hash with a dependabot-readable version comment.Tags expanded in this repo:
MiraGeoscience/CI-tools/.github/workflows/reusable-jira-issue_to_jira.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-jira-pr_actions.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-python-static_analysis.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-python-pytest.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_rattler_package.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_pypi_package.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_conda_assets.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_pypi_assets.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-advanced-security.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-annotate.yml@v3 -> @v3.12.0Workflows added:
.github/workflows/dependabot-auto-merge.yml.github/workflows/wip-status.ymlAll
MiraGeoscience/CI-toolsreusable workflows are pinned to7241532854727d993872b67fc761139b8438615b(v3.12.0).