Skip to content

Pin GitHub Actions to commit SHAs - #3259

Open
github-security-bot wants to merge 1 commit into
mainfrom
pinner/actions-sha-pins-2026-09-10
Open

Pin GitHub Actions to commit SHAs#3259
github-security-bot wants to merge 1 commit into
mainfrom
pinner/actions-sha-pins-2026-09-10

Conversation

@github-security-bot

@github-security-bot github-security-bot commented Sep 10, 2026

Copy link
Copy Markdown

Pins GitHub Actions uses: references in github/github-mcp-server to immutable commit SHAs.

Summary

Metric Count
Files changed 13
Files scanned 12
Refs found 34
Refs pinned 34
Skipped refs 0
Warnings 0
Errors 0

Why

Pinning actions to full commit SHAs prevents future tag or branch retargeting from changing workflow behavior without review.

Reviewer notes

  • Original refs are preserved in inline comments when possible.
  • Pin comments use the Dependabot-compatible original-ref style.
  • Branch refs were allowed and pinned to their current HEAD; review mutable-branch pins carefully.
  • No minimum action age was enforced for this run.

Pinned refs

Location Before After Resolved as
.github/workflows/ai-issue-assessment.yml:17 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/close-inactive-issues.yml:17 actions/stale@v11 actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93 tag
.github/workflows/code-scanning.yml:44 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/code-scanning.yml:47 github/codeql-action/init@v4.37.9 github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 tag
.github/workflows/code-scanning.yml:64 github/codeql-action/start-proxy@v4.37.9 github/codeql-action/start-proxy@cdf488f595d80d6e07e03d4674febd5ab45fa938 tag
.github/workflows/code-scanning.yml:70 github/codeql-action/resolve-environment@v4.37.9 github/codeql-action/resolve-environment@cdf488f595d80d6e07e03d4674febd5ab45fa938 tag
.github/workflows/code-scanning.yml:75 actions/setup-go@v7 actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e tag
.github/workflows/code-scanning.yml:83 actions/setup-node@v7 actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 tag
.github/workflows/code-scanning.yml:94 github/codeql-action/autobuild@v4.37.9 github/codeql-action/autobuild@cdf488f595d80d6e07e03d4674febd5ab45fa938 tag
.github/workflows/code-scanning.yml:97 github/codeql-action/analyze@v4.37.9 github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 tag
.github/workflows/docker-publish.yml:43 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/docker-publish.yml:90 actions/cache@v6 actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 tag
.github/workflows/docs-check.yml:17 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/docs-check.yml:23 actions/setup-go@v7 actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e tag
.github/workflows/go.yml:26 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/go.yml:32 actions/setup-go@v7 actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e tag
.github/workflows/goreleaser.yml:17 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/goreleaser.yml:23 actions/setup-go@v7 actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e tag
.github/workflows/goreleaser.yml:45 actions/attest-build-provenance@v4 actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 tag
.github/workflows/license-check.yml:27 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/license-check.yml:39 actions/setup-go@v7 actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e tag
.github/workflows/license-check.yml:73 actions/github-script@v9 actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 tag
.github/workflows/license-check.yml:91 actions/github-script@v9 actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 tag
.github/workflows/lint.yml:16 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/lint.yml:19 actions/setup-go@v7 actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e tag
.github/workflows/lint.yml:23 golangci/golangci-lint-action@v9 golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a tag
.github/workflows/mcp-diff.yml:18 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/mcp-diff.yml:23 actions/setup-go@v7 actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e tag
.github/workflows/mcp-diff.yml:88 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/mcp-diff.yml:93 actions/setup-go@v7 actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e tag
.github/workflows/moderator.yml:19 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/moderator.yml:20 github/ai-moderator@v1 github/ai-moderator@81159c370785e295c97461ade67d7c33576e9319 tag
.github/workflows/registry-releaser.yml:17 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/registry-releaser.yml:20 actions/setup-go@v7 actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e tag

Dependabot

  • Added a 7-day cooldown (cooldown: default-days: 7) to the existing github-actions Dependabot configuration.
  • The cooldown delays applying a newly published action release for 7 days, reducing exposure to a compromised or broken release while keeping you SHA-pinned.

Generated by pinner 0.1.0.

Copilot AI balanced review requested due to automatic review settings September 10, 2026 21:28
@github-security-bot
github-security-bot requested a review from a team as a code owner September 10, 2026 21:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The local build-ui composite action still contains two mutable external action references.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Pins direct workflow action dependencies to immutable SHAs and adds a Dependabot update cooldown.

Changes:

  • Pins 34 workflow action references with version comments.
  • Adds a seven-day GitHub Actions cooldown.
File summaries
File Description
.github/workflows/registry-releaser.yml Pins checkout and Go setup.
.github/workflows/moderator.yml Pins checkout and moderation actions.
.github/workflows/mcp-diff.yml Pins checkout and Go setup.
.github/workflows/lint.yml Pins lint workflow actions.
.github/workflows/license-check.yml Pins license-check actions.
.github/workflows/goreleaser.yml Pins release and attestation actions.
.github/workflows/go.yml Pins build workflow actions.
.github/workflows/docs-check.yml Pins documentation-check actions.
.github/workflows/docker-publish.yml Pins checkout and cache actions.
.github/workflows/code-scanning.yml Pins CodeQL and setup actions.
.github/workflows/close-inactive-issues.yml Pins the stale action.
.github/workflows/ai-issue-assessment.yml Pins checkout.
.github/dependabot.yml Adds a seven-day cooldown.
Review details
  • Files reviewed: 13/13 changed files
  • Comments generated: 1
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

- name: Build UI
uses: ./.github/actions/build-ui
- uses: actions/setup-go@v7
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
@tiagovilasboas

Copy link
Copy Markdown

Staff AppSec (Actions SHA pinning)

Verdict: Approve with a small follow-up (conversation comment — formal review UI often disabled here.)

Pinning 34 workflow uses: refs to full commit SHAs (+ Dependabot github-actions 7-day cooldown) is the right supply-chain default: tag retargets can no longer silently change CI. Comment style is Dependabot-friendly.

Please follow up (or amend): .github/actions/build-ui/action.yml still uses mutable actions/cache@v5 and actions/setup-node@v6. That composite is on the hot path for go/lint/docs/license/code-scanning/goreleaser/mcp-diff — pinning workflows alone leaves a second mutable hop. Same # vX.Y.Z comment style as the rest of this PR.

Otherwise LGTM from AppSec.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants