Skip to content

ci: pin GitHub Actions to full-length commit SHAs - #2318

Merged
XianBW (XianBW) merged 3 commits into
microsoft:mainfrom
danfiedler-msft:danfiedler/pin-actions
Sep 16, 2026
Merged

XianBW (XianBW) merged 3 commits into
microsoft:mainfrom
danfiedler-msft:danfiedler/pin-actions

Conversation

@danfiedler-msft

@danfiedler-msft Dan Fiedler (danfiedler-msft) commented Aug 12, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Pin all 23 remote GitHub Action references across the six workflows to full-length commit SHAs, and add grouped weekly Dependabot updates with a seven-day cooldown.

This branch now incorporates the CI compatibility fixes merged in #2308 (main commit f431588906e776123332a32bbf82b5f828006fda). Merge conflicts are resolved without reverting those fixes.

Changes

Action pinning

  • Preserve main's checkout/setup-python/setup-node v6 and retry v4 versions in the title and Python-test workflows, and pin their upstream commit SHAs with version comments.
  • Include every download and configuration-execution retry step introduced by ci: fix dependency compatibility failures #2308.
  • Retain the original PR's release/stale action pins; this PR does not otherwise upgrade or redesign those workflows.
  • Keep workflow configuration identical to main apart from action references: Node 22 and locked commitlint installation, shared Python constraints, dependency profiles, macOS libomp preparation order, bounded retries, and all 75 Python matrix jobs remain intact.
  • Add an offline policy test covering remote action references and reusable-workflow references, rejecting mutable tags.

Full-length SHA pinning prevents a moved action tag from changing the selected commit. It does not lock dependencies fetched dynamically by an action or guarantee that the pinned code is free of vulnerabilities. See the GitHub Actions security guidance and action-pinning guidance.

Dependabot

  • Check the github-actions ecosystem weekly.
  • Group matching action version updates into one group.
  • Explicitly set commit-message.prefix: ci and include: scope to align generated titles with commitlint; an offline policy test protects this configuration.
  • Set cooldown.default-days: 7 so newly published versions wait through the cooldown before becoming eligible for a version-update PR.

The cooldown is based on release age, not a minimum interval between successive PRs; the weekly schedule controls the check frequency. See the Dependabot options reference.

Validation

Completed GitHub Actions validation

The action-pinning and main-integration commit 107e0a4ee56fbf13bead574806fb9accfd002043 passed the complete CI suite:

Workflow Result
Source tests 25/25 passed
Slow source tests 25/25 passed
PyPI tests 25/25 passed
Title lint Passed

All 75 matrix jobs passed. All 23 remote action references were checked against their upstream versions, and YAML comparison confirmed workflow settings otherwise match main. A negative regression check confirmed mutable action tags are rejected. Static validation passed for the title, three Python-test, and stale workflows.

Latest review follow-up

Current head: 13fe94afc4bd8ee74160a64ad2803660dee43ee8.

This follow-up only adds the explicit Dependabot commit-message configuration, its regression test, and maintenance documentation. It does not change workflow execution or Python dependencies.

Local validation on the current head:

  • All 15 CI configuration-policy tests pass.
  • Black and diff checks pass.
  • The representative title ci(deps): bump the github-actions group with 3 updates passes the locked commitlint configuration.

New CI runs for this head have been triggered: Source, Slow, and PyPI. Their results are pending; the completed 75/75 results above apply to the preceding commit, not this new head.

Existing limitation

release.yml already references an undefined matrix.python-version in its non-matrix manylinux job; static validation reproduces this on main. Its old setup-python runtime is also flagged when validating main's tag-based reference. This PR only pins the existing release actions and does not fix or execute the publishing workflow.

@XianBW XianBW (XianBW) changed the title Pin GitHub Actions to full-length commit SHAs ci: Pin GitHub Actions to full-length commit SHAs Sep 15, 2026
@XianBW XianBW (XianBW) changed the title ci: Pin GitHub Actions to full-length commit SHAs ci: pin GitHub Actions to full-length commit SHAs Sep 16, 2026
@XianBW
XianBW (XianBW) merged commit be72549 into microsoft:main Sep 16, 2026
78 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants