DEVOPS-1133: Pin GitHub Actions to commit hashes - #215
Conversation
There was a problem hiding this comment.
Pull request overview
This PR updates GitHub Actions reusable-workflow references in this repository from the floating @v3 major tag to the more specific @v3.9.1 tag for MiraGeoscience/CI-tools, as a step toward tighter supply-chain pinning of CI dependencies.
Changes:
- Updated Zizmor reusable workflows to
@v3.9.1. - Updated Python analysis, deploy (dev/prod), and JIRA automation reusable workflows to
@v3.9.1. - Standardized CI-tools workflow references across all local workflows touched in this repo.
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/security_scan.yml | Bumps Zizmor reusable workflow references from @v3 to @v3.9.1. |
| .github/workflows/python_deploy_prod.yml | Bumps production release reusable workflows from @v3 to @v3.9.1. |
| .github/workflows/python_deploy_dev.yml | Bumps development publish reusable workflows from @v3 to @v3.9.1. |
| .github/workflows/python_analysis.yml | Bumps analysis and pytest reusable workflows from @v3 to @v3.9.1. |
| .github/workflows/pr_jira_actions.yml | Bumps JIRA PR actions reusable workflow from @v3 to @v3.9.1. |
| .github/workflows/issue_to_jira.yml | Bumps “issue to JIRA” reusable workflow from @v3 to @v3.9.1. |
Comments suppressed due to low confidence (4)
.github/workflows/python_analysis.yml:39
- This still references the reusable workflow by semver tag (
@v3.9.1). The PR title/description saysuses:should be pinned to a commit hash with a dependabot-readable version comment. Pin to the commit behindv3.9.1and add# v3.9.1.
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-pytest.yml@v3.9.1
.github/workflows/python_deploy_dev.yml:32
- This still references the reusable workflow by semver tag (
@v3.9.1). The PR title/description saysuses:should be pinned to a commit hash with a dependabot-readable version comment. Pin to the commit behindv3.9.1and add# v3.9.1.
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_pypi_package.yml@v3.9.1
.github/workflows/python_deploy_prod.yml:44
- This still references the reusable workflow by semver tag (
@v3.9.1). The PR title/description saysuses:should be pinned to a commit hash with a dependabot-readable version comment. Pin to the commit behindv3.9.1and add# v3.9.1.
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_pypi_assets.yml@v3.9.1
.github/workflows/security_scan.yml:43
- This still references the reusable workflow by semver tag (
@v3.9.1). The PR title/description saysuses:should be pinned to a commit hash with a dependabot-readable version comment. Pin to the commit behindv3.9.1and add# v3.9.1.
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-annotate.yml@v3.9.1
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
…voids Windows glob bug)
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #215 +/- ##
===========================================
+ Coverage 85.70% 85.95% +0.25%
===========================================
Files 19 19
Lines 1196 1196
Branches 155 155
===========================================
+ Hits 1025 1028 +3
+ Misses 129 127 -2
+ Partials 42 41 -1 🚀 New features to boost your workflow:
|
DEVOPS-1133 - pin all GitHub actions and reusable workflows to hash
Expands moving GitHub Actions tags to the full semver tag pointing at the same commit, then pins every
uses:to a commit hash with a dependabot-readable version comment.Tags expanded in this repo:
MiraGeoscience/CI-tools/.github/workflows/reusable-jira-issue_to_jira.yml@v3 -> @v3.9.1MiraGeoscience/CI-tools/.github/workflows/reusable-jira-pr_actions.yml@v3 -> @v3.9.1MiraGeoscience/CI-tools/.github/workflows/reusable-python-static_analysis.yml@v3 -> @v3.9.1MiraGeoscience/CI-tools/.github/workflows/reusable-python-pytest.yml@v3 -> @v3.9.1MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_rattler_package.yml@v3 -> @v3.9.1MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_pypi_package.yml@v3 -> @v3.9.1MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_conda_assets.yml@v3 -> @v3.9.1MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_pypi_assets.yml@v3 -> @v3.9.1MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-advanced-security.yml@v3 -> @v3.9.1MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-annotate.yml@v3 -> @v3.9.1