Repository navigation
ci: pin GitHub Actions to commit SHAs - #1314
Open
chopmob-cloud wants to merge 1 commit into
Open
chopmob-cloud wants to merge 1 commit into
chopmob-cloud wants to merge 1 commit into
Conversation
Pin the GitHub Actions in .github/workflows to full-length commit SHAs with version comments. A mutable tag can be re-pointed after review, so pinning to a commit SHA is the OpenSSF Scorecard Pinned-Dependencies control. Ref-pinning only, same versions, no functional change. Generated with pinact; each SHA verified to resolve to its version tag. Signed-off-by: AlgoVoi <chopmob@gmail.com>
🧪 Code Coverage (vs
|
| Base | PR | Delta | |
|---|---|---|---|
| src/a2a/server/cluster/database_event_stream.py | 92.86% | 96.94% | 🟢 +4.08% |
| Total | 92.99% | 93.03% | 🟢 +0.04% |
Generated by coverage-comment.yml
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pins the GitHub Actions in
.github/workflowsto full-length commit SHAs with# vXversion comments, bringing this repo in line with the sibling repo a2a-go, which is already fully pinned.Why
A mutable tag like
@v7can be moved to new code after review, so a compromised or hijacked action tag would run with this workflow's permissions. Pinning to a commit SHA is the OpenSSF Scorecard "Pinned-Dependencies" control and the GitHub-recommended practice. This repo already runs Dependabot for thegithub-actionsecosystem, so Dependabot keeps the SHA pins current (it bumps the SHA and the# vXcomment together).What
uses:across 10 workflow files to its exact commit SHA, keeping a# vXversion comment. Same versions, no upgrades or downgrades.pinact; each pinned SHA was verified to resolve to the version in its comment via the GitHub API.# vXcomment expanded to the exact version (same SHA).