Skip to content

ci(security): pin GitHub Actions to commit SHAs, harden checkout (fixes zizmor gate for all PRs) - #164

Open
RanjithRagavan wants to merge 1 commit into
google:mainfrom
RanjithRagavan:ci/pin-action-shas
Open

RanjithRagavan wants to merge 1 commit into
google:mainfrom
RanjithRagavan:ci/pin-action-shas

Conversation

@RanjithRagavan

Copy link
Copy Markdown

Summary

The repository's mandatory GitHub Actions security scan (zizmor, zizmor-output job) currently fails every open PR — including #153 — with 10 unpinned action reference findings: all actions in ci.yml are pinned to mutable tags (@v4, @v5, @v6) rather than commit SHAs.

This PR fixes the root cause so the security gate goes green repo-wide.

Changes (.github/workflows/ci.yml only)

  • Pin all 10 action references to commit SHAs, keeping the version tag as a trailing comment for readability and Dependabot compatibility:
    • actions/checkout → 11d5960a… # v4 (3 uses)
    • actions/setup-python → a26af69b… # v5 (2 uses)
    • astral-sh/setup-uv → d0cc045d… # v6 (2 uses)
    • actions/setup-node → 49933ea5… # v4 (2 uses)
    • actions/upload-artifact → ea165f8d… # v4 (1 use)
  • Harden checkout: persist-credentials: false on all three actions/checkout steps (clears zizmor's artipacked findings; CI only reads the repo, so no behavior change)

Verification

  • zizmor .github/workflows/ci.yml locally: zero findings (was: 10 unpinned-refs errors + 3 artipacked mediums)
  • No workflow logic changed — same actions, same versions, immutable references

Once this merges, the zizmor-output gate should pass for #132, #153, and all future PRs. Dependabot already tracks these actions (.github/dependabot.yml covers github-actions) and will keep the pinned SHAs updated automatically.

The repository's mandatory Actions security scan (zizmor) fails all PRs
with 'unpinned action reference' findings against ci.yml (actions pinned
to mutable tags like @v4). Pin all 10 action references to their current
commit SHAs, keeping the version tag as a trailing comment for
readability and Dependabot compatibility, and set
persist-credentials: false on all checkout steps (artipacked audit).

Verified locally: zizmor reports zero findings on the pinned workflow.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant