ci: pin GitHub Actions to full-length commit SHAs - #2318
Merged
XianBW (XianBW) merged 3 commits intoSep 16, 2026
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Pin all 23 remote GitHub Action references across the six workflows to full-length commit SHAs, and add grouped weekly Dependabot updates with a seven-day cooldown.
This branch now incorporates the CI compatibility fixes merged in #2308 (main commit
f431588906e776123332a32bbf82b5f828006fda). Merge conflicts are resolved without reverting those fixes.Changes
Action pinning
Full-length SHA pinning prevents a moved action tag from changing the selected commit. It does not lock dependencies fetched dynamically by an action or guarantee that the pinned code is free of vulnerabilities. See the GitHub Actions security guidance and action-pinning guidance.
Dependabot
github-actionsecosystem weekly.commit-message.prefix: ciandinclude: scopeto align generated titles with commitlint; an offline policy test protects this configuration.cooldown.default-days: 7so newly published versions wait through the cooldown before becoming eligible for a version-update PR.The cooldown is based on release age, not a minimum interval between successive PRs; the weekly schedule controls the check frequency. See the Dependabot options reference.
Validation
Completed GitHub Actions validation
The action-pinning and main-integration commit
107e0a4ee56fbf13bead574806fb9accfd002043passed the complete CI suite:All 75 matrix jobs passed. All 23 remote action references were checked against their upstream versions, and YAML comparison confirmed workflow settings otherwise match main. A negative regression check confirmed mutable action tags are rejected. Static validation passed for the title, three Python-test, and stale workflows.
Latest review follow-up
Current head:
13fe94afc4bd8ee74160a64ad2803660dee43ee8.This follow-up only adds the explicit Dependabot commit-message configuration, its regression test, and maintenance documentation. It does not change workflow execution or Python dependencies.
Local validation on the current head:
ci(deps): bump the github-actions group with 3 updatespasses the locked commitlint configuration.New CI runs for this head have been triggered: Source, Slow, and PyPI. Their results are pending; the completed 75/75 results above apply to the preceding commit, not this new head.
Existing limitation
release.ymlalready references an undefinedmatrix.python-versionin its non-matrix manylinux job; static validation reproduces this on main. Its old setup-python runtime is also flagged when validating main's tag-based reference. This PR only pins the existing release actions and does not fix or execute the publishing workflow.