From ab22b34f17fbcf7e95473cc6e802302621c4d5cf Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Nerijus=20Bend=C5=BEi=C5=ABnas?= Date: Sat, 29 Aug 2026 20:56:00 +0300 Subject: [PATCH] ci: reduce ratchet pin comments to bare versions MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit zizmor treats `# ratchet:owner/action@vX` as a resolvable reference it cannot trust; a plain version comment keeps the SHA pin self-describing without it. Major-only aliases (v6, v7, v8, v1) resolved to the full tag each SHA carries. Signed-off-by: Nerijus Bendžiūnas --- .github/workflows/coverage-baseline.yml | 6 +++--- .github/workflows/coverage-comment.yml | 6 +++--- .github/workflows/lint-md.yml | 2 +- .github/workflows/lint-workflows.yml | 10 +++++----- .github/workflows/release.yml | 2 +- .github/workflows/test.yml | 2 +- 6 files changed, 14 insertions(+), 14 deletions(-) diff --git a/.github/workflows/coverage-baseline.yml b/.github/workflows/coverage-baseline.yml index 44bf7f2..9a2a7d2 100644 --- a/.github/workflows/coverage-baseline.yml +++ b/.github/workflows/coverage-baseline.yml @@ -11,12 +11,12 @@ jobs: steps: - name: Checkout code # yamllint disable-line rule:line-length - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # ratchet:actions/checkout@v6 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Install uv # yamllint disable-line rule:line-length - uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # ratchet:astral-sh/setup-uv@v8.2.0 + uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0 - name: Cache NLTK data # yamllint disable-line rule:line-length uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4 @@ -27,7 +27,7 @@ jobs: run: uv run --dev pytest tests/ --cov=git_commit_guard --cov-report=xml - name: Upload coverage baseline # yamllint disable-line rule:line-length - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # ratchet:actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: main-coverage path: coverage.xml diff --git a/.github/workflows/coverage-comment.yml b/.github/workflows/coverage-comment.yml index fa8bff3..1759399 100644 --- a/.github/workflows/coverage-comment.yml +++ b/.github/workflows/coverage-comment.yml @@ -16,7 +16,7 @@ jobs: steps: - name: Download artifact # yamllint disable-line rule:line-length - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # ratchet:actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: run-id: ${{ github.event.workflow_run.id }} name: pr @@ -57,7 +57,7 @@ jobs: - name: Download baseline coverage if: steps.baseline.outputs.run-id != '' # yamllint disable-line rule:line-length - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # ratchet:actions/download-artifact@v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: run-id: ${{ steps.baseline.outputs.run-id }} name: main-coverage @@ -89,7 +89,7 @@ jobs: PYEOF - name: Post coverage comment # yamllint disable-line rule:line-length - uses: MishaKav/pytest-coverage-comment@dd5b80bde6d16941f336518e92929e89069d8451 # ratchet:MishaKav/pytest-coverage-comment@v1.7.2 + uses: MishaKav/pytest-coverage-comment@dd5b80bde6d16941f336518e92929e89069d8451 # v1.7.2 with: pytest-xml-coverage-path: coverage.xml unique-id-for-comment: coverage diff --git a/.github/workflows/lint-md.yml b/.github/workflows/lint-md.yml index e878656..d3e9a5c 100644 --- a/.github/workflows/lint-md.yml +++ b/.github/workflows/lint-md.yml @@ -42,7 +42,7 @@ jobs: enable-cache: false - name: Set up reviewdog # yamllint disable-line rule:line-length - uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # ratchet:reviewdog/action-setup@v1 + uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # v1.5.0 - name: Lint Markdown files with rumdl via reviewdog env: REVIEWDOG_GITHUB_API_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/lint-workflows.yml b/.github/workflows/lint-workflows.yml index f6d6405..2890d61 100644 --- a/.github/workflows/lint-workflows.yml +++ b/.github/workflows/lint-workflows.yml @@ -17,7 +17,7 @@ jobs: persist-credentials: false - name: Run actionlint # yamllint disable-line rule:line-length - uses: reviewdog/action-actionlint@6fb7acc99f4a1008869fa8a0f09cfca740837d9d # ratchet:reviewdog/action-actionlint@v1 + uses: reviewdog/action-actionlint@6fb7acc99f4a1008869fa8a0f09cfca740837d9d # v1.72.0 with: github_token: ${{ github.token }} reporter: github-pr-review @@ -34,10 +34,10 @@ jobs: persist-credentials: false - name: Set up uv # yamllint disable-line rule:line-length - uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # ratchet:astral-sh/setup-uv@v8.2.0 + uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0 - name: Set up reviewdog # yamllint disable-line rule:line-length - uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # ratchet:reviewdog/action-setup@v1 + uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # v1.5.0 - name: Run yamlfix env: REVIEWDOG_GITHUB_API_TOKEN: ${{ github.token }} @@ -59,10 +59,10 @@ jobs: persist-credentials: false - name: Set up uv # yamllint disable-line rule:line-length - uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # ratchet:astral-sh/setup-uv@v8.2.0 + uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0 - name: Set up reviewdog # yamllint disable-line rule:line-length - uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # ratchet:reviewdog/action-setup@v1 + uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # v1.5.0 - name: Run zizmor env: REVIEWDOG_GITHUB_API_TOKEN: ${{ github.token }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 802f504..4790e59 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -31,7 +31,7 @@ jobs: - name: Generate release notes id: git-cliff # yamllint disable-line rule:line-length - uses: orhun/git-cliff-action@f50e11560dce63f7c33227798f90b924471a88b5 # ratchet:orhun/git-cliff-action@v4.8.0 + uses: orhun/git-cliff-action@f50e11560dce63f7c33227798f90b924471a88b5 # v4.8.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 701bc75..5849c87 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -35,7 +35,7 @@ jobs: cp coverage.xml ./pr/ - name: Upload PR artifact # yamllint disable-line rule:line-length - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # ratchet:actions/upload-artifact@v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: pr path: pr/