Skip to content

Pin GitHub Actions to commit SHAs - #3747

Open
github-security-bot wants to merge 1 commit into
mainfrom
pinner/actions-sha-pins-2026-09-10
Open

Pin GitHub Actions to commit SHAs#3747
github-security-bot wants to merge 1 commit into
mainfrom
pinner/actions-sha-pins-2026-09-10

Conversation

@github-security-bot

@github-security-bot github-security-bot commented Sep 10, 2026

Copy link
Copy Markdown

Pins GitHub Actions uses: references in github/opensource.guide to immutable commit SHAs.

Summary

Metric Count
Files changed 6
Files scanned 5
Refs found 12
Refs pinned 12
Skipped refs 0
Warnings 0
Errors 0

Why

Pinning actions to full commit SHAs prevents future tag or branch retargeting from changing workflow behavior without review.

Reviewer notes

  • Original refs are preserved in inline comments when possible.
  • Pin comments use the Dependabot-compatible original-ref style.
  • Branch refs were allowed and pinned to their current HEAD; review mutable-branch pins carefully.
  • No minimum action age was enforced for this run.

Pinned refs

Location Before After Resolved as
.github/workflows/codeql.yml:55 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/codeql.yml:58 github/codeql-action/init@v4 github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 tag
.github/workflows/codeql.yml:75 github/codeql-action/analyze@v4 github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 tag
.github/workflows/jekyll.yml:30 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/jekyll.yml:32 actions/configure-pages@v6.0.0 actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d tag
.github/workflows/jekyll.yml:40 actions/upload-pages-artifact@v5.0.0 actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 tag
.github/workflows/jekyll.yml:51 actions/deploy-pages@v5.0.1 actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 tag
.github/workflows/link-check.yml:14 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/link-check.yml:20 actions/setup-node@v7.0.0 actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 tag
.github/workflows/stale.yml:14 actions/stale@v11.0.0 actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93 tag
.github/workflows/tests.yml:14 actions/checkout@v7 actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 tag
.github/workflows/tests.yml:20 actions/setup-node@v7.0.0 actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 tag

Dependabot

  • Added a 7-day cooldown (cooldown: default-days: 7) to the existing github-actions Dependabot configuration.
  • The cooldown delays applying a newly published action release for 7 days, reducing exposure to a compromised or broken release while keeping you SHA-pinned.

Generated by pinner 0.1.0.

Copilot AI balanced review requested due to automatic review settings September 10, 2026 21:30
@github-security-bot
github-security-bot requested a review from a team as a code owner September 10, 2026 21:30

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃煝 Approval recommended

The SHAs match their documented tags, all action references are immutable, and the changed YAML parses successfully.

Pull request overview

Pins all mutable GitHub Actions references to verified, immutable commit SHAs.

Changes:

  • Pins 12 action references with version comments.
  • Adds a seven-day Dependabot cooldown for Actions updates.
File summaries
File Description
.github/workflows/tests.yml Pins test workflow actions.
.github/workflows/stale.yml Pins the stale action.
.github/workflows/link-check.yml Pins link-check actions.
.github/workflows/jekyll.yml Pins Pages build and deployment actions.
.github/workflows/codeql.yml Pins checkout and CodeQL actions.
.github/dependabot.yml Adds the Actions update cooldown.
Review details
  • Files reviewed: 6/6 changed files
  • Comments generated: 0
  • Review effort level: Balanced

馃挕 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants