Skip to content

馃敀 security: pin release action to immutable commit - #4

Merged
warengonzaga merged 1 commit into
devfrom
fix/pin-release-action
Sep 28, 2026
Merged

warengonzaga merged 1 commit into
devfrom
fix/pin-release-action

Conversation

@warengonzaga

Copy link
Copy Markdown
Member

Pin both release planning and publication invocations to full commit 6df9cb42c24c296d902150d051a0b6be4422cccc, the inspected commit behind v1. This prevents a later tag move from silently replacing privileged workflow code.

Addresses the mutable-action review on release PR #2. YAML parsing, checks that both invocations share the pin, and git diff --check passed. Hosted release execution was not run.

Copilot AI lite review requested due to automatic review settings September 28, 2026 18:11
@warengonzaga warengonzaga added security [Type] Security vulnerability or hardening [issues, PRs] infra [Area] Build system, CI/CD, deployment, config, and DevOps [issues, PRs] labels Sep 28, 2026
@warengonzaga
warengonzaga merged commit 998b1f9 into dev Sep 28, 2026
1 check passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

馃煝 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: None

What changed in this PR

Pins both release workflow action invocations to immutable commit 6df9cb42c24c296d902150d051a0b6be4422cccc, preventing mutable tag replacement.

Changes:

  • Replaced both @v1 references with the full commit SHA.
  • Kept planning and publication steps on the same pinned revision.
File Description
.github/鈥媤orkflows/鈥媟elease.yml Pins both release actions immutably.

馃挕 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

infra [Area] Build system, CI/CD, deployment, config, and DevOps [issues, PRs] security [Type] Security vulnerability or hardening [issues, PRs]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants