Skip to content

DEVOPS-1133: Pin GitHub Actions to commit hashes - #215

Open
RomFloreani wants to merge 2 commits into
developfrom
DEVOPS-1133
Open

DEVOPS-1133: Pin GitHub Actions to commit hashes#215
RomFloreani wants to merge 2 commits into
developfrom
DEVOPS-1133

Conversation

@RomFloreani

@RomFloreani RomFloreani commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

DEVOPS-1133 - pin all GitHub actions and reusable workflows to hash
Expands moving GitHub Actions tags to the full semver tag pointing at the same commit, then pins every uses: to a commit hash with a dependabot-readable version comment.

Tags expanded in this repo:

  • MiraGeoscience/CI-tools/.github/workflows/reusable-jira-issue_to_jira.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-jira-pr_actions.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-static_analysis.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-pytest.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_rattler_package.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_pypi_package.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_conda_assets.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_pypi_assets.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-advanced-security.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-annotate.yml@v3 -> @v3.9.1

Copilot AI review requested due to automatic review settings July 29, 2026 16:38
@github-actions github-actions Bot changed the title Pin GitHub Actions to commit hashes DEVOPS-1133: Pin GitHub Actions to commit hashes Jul 29, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates GitHub Actions reusable-workflow references in this repository from the floating @v3 major tag to the more specific @v3.9.1 tag for MiraGeoscience/CI-tools, as a step toward tighter supply-chain pinning of CI dependencies.

Changes:

  • Updated Zizmor reusable workflows to @v3.9.1.
  • Updated Python analysis, deploy (dev/prod), and JIRA automation reusable workflows to @v3.9.1.
  • Standardized CI-tools workflow references across all local workflows touched in this repo.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 6 comments.

Show a summary per file
File Description
.github/workflows/security_scan.yml Bumps Zizmor reusable workflow references from @v3 to @v3.9.1.
.github/workflows/python_deploy_prod.yml Bumps production release reusable workflows from @v3 to @v3.9.1.
.github/workflows/python_deploy_dev.yml Bumps development publish reusable workflows from @v3 to @v3.9.1.
.github/workflows/python_analysis.yml Bumps analysis and pytest reusable workflows from @v3 to @v3.9.1.
.github/workflows/pr_jira_actions.yml Bumps JIRA PR actions reusable workflow from @v3 to @v3.9.1.
.github/workflows/issue_to_jira.yml Bumps “issue to JIRA” reusable workflow from @v3 to @v3.9.1.
Comments suppressed due to low confidence (4)

.github/workflows/python_analysis.yml:39

  • This still references the reusable workflow by semver tag (@v3.9.1). The PR title/description says uses: should be pinned to a commit hash with a dependabot-readable version comment. Pin to the commit behind v3.9.1 and add # v3.9.1.
    uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-pytest.yml@v3.9.1

.github/workflows/python_deploy_dev.yml:32

  • This still references the reusable workflow by semver tag (@v3.9.1). The PR title/description says uses: should be pinned to a commit hash with a dependabot-readable version comment. Pin to the commit behind v3.9.1 and add # v3.9.1.
    uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_pypi_package.yml@v3.9.1

.github/workflows/python_deploy_prod.yml:44

  • This still references the reusable workflow by semver tag (@v3.9.1). The PR title/description says uses: should be pinned to a commit hash with a dependabot-readable version comment. Pin to the commit behind v3.9.1 and add # v3.9.1.
    uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_pypi_assets.yml@v3.9.1

.github/workflows/security_scan.yml:43

  • This still references the reusable workflow by semver tag (@v3.9.1). The PR title/description says uses: should be pinned to a commit hash with a dependabot-readable version comment. Pin to the commit behind v3.9.1 and add # v3.9.1.
    uses: MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-annotate.yml@v3.9.1

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/issue_to_jira.yml Outdated
Comment thread .github/workflows/pr_jira_actions.yml Outdated
Comment thread .github/workflows/python_analysis.yml Outdated
Comment thread .github/workflows/python_deploy_dev.yml Outdated
Comment thread .github/workflows/python_deploy_prod.yml Outdated
Comment thread .github/workflows/security_scan.yml Outdated
Copilot AI review requested due to automatic review settings July 29, 2026 17:27

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated no new comments.

@codecov

codecov Bot commented Jul 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.95%. Comparing base (7238a55) to head (9b9bc84).

Additional details and impacted files
@@             Coverage Diff             @@
##           develop     #215      +/-   ##
===========================================
+ Coverage    85.70%   85.95%   +0.25%     
===========================================
  Files           19       19              
  Lines         1196     1196              
  Branches       155      155              
===========================================
+ Hits          1025     1028       +3     
+ Misses         129      127       -2     
+ Partials        42       41       -1     

see 1 file with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants