DEVOPS-1133: Pin GitHub Actions to commit hashes - #456
Conversation
There was a problem hiding this comment.
Pull request overview
This PR updates this repository’s GitHub Actions reusable-workflow references to use the MiraGeoscience/CI-tools v3.9.1 tag instead of the floating v3 major tag across all workflows.
Changes:
- Updated all
uses: MiraGeoscience/CI-tools/...@v3references to@v3.9.1. - Applied the same version bump consistently across security scan, Python analysis/deploy, and JIRA automation workflows.
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/security_scan.yml | Updates Zizmor reusable workflow references from v3 to v3.9.1. |
| .github/workflows/python_deploy_prod.yml | Updates Conda/PyPI production release reusable workflow references from v3 to v3.9.1. |
| .github/workflows/python_deploy_dev.yml | Updates Conda/PyPI development publish reusable workflow references from v3 to v3.9.1. |
| .github/workflows/python_analysis.yml | Updates static analysis and pytest reusable workflow references from v3 to v3.9.1. |
| .github/workflows/pr_jira_actions.yml | Updates PR→JIRA reusable workflow reference from v3 to v3.9.1. |
| .github/workflows/issue_to_jira.yml | Updates issue→JIRA reusable workflow reference from v3 to v3.9.1. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #456 +/- ##
========================================
Coverage 90.45% 90.45%
========================================
Files 113 113
Lines 6987 6987
Branches 862 862
========================================
Hits 6320 6320
Misses 451 451
Partials 216 216 🚀 New features to boost your workflow:
|
| name: Dependabot auto-merge | ||
|
|
||
| on: | ||
| pull_request_target: # zizmor: ignore[dangerous-triggers] no checkout, no execution of PR-authored code; only trusted event context is read |
There was a problem hiding this comment.
| pull_request_target: # zizmor: ignore[dangerous-triggers] no checkout, no execution of PR-authored code; only trusted event context is read | |
| pull_request: |
3a95650 to
df47b46
Compare
|
|
Pin all GitHub Actions and reusable workflow references to immutable commit hashes, and add the dependabot auto-merge and WIP status workflows.
2c74808 to
4be23f2
Compare
|
|
DEVOPS-1133 - pin all GitHub actions and reusable workflows to hash
Expands moving GitHub Actions tags to the full semver tag pointing at the same commit, then pins every
uses:to a commit hash with a dependabot-readable version comment.Tags expanded in this repo:
MiraGeoscience/CI-tools/.github/workflows/reusable-jira-issue_to_jira.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-jira-pr_actions.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-python-static_analysis.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-python-pytest.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_rattler_package.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_pypi_package.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_conda_assets.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_pypi_assets.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-advanced-security.yml@v3 -> @v3.12.0MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-annotate.yml@v3 -> @v3.12.0Workflows added:
.github/workflows/dependabot-auto-merge.yml.github/workflows/wip-status.ymlAll
MiraGeoscience/CI-toolsreusable workflows are pinned to7241532854727d993872b67fc761139b8438615b(v3.12.0).