Repository navigation
Upgrade all third-party actions and pin them to immutable releases - #163
Conversation
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v4 | ||
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd |
There was a problem hiding this comment.
actions/checkout does not use immutable releases, so we need to pin to the commit hash for the most recent release.
|
|
||
| - name: Install uv | ||
| uses: astral-sh/setup-uv@v5 | ||
| uses: astral-sh/setup-uv@v8.1.0 |
There was a problem hiding this comment.
astral-sh/setup-uv does use immutable releases, so we can pin to a specific version and have confidence that a malicious actor cannot change it. We can confirm that the release is immutable by looking for the 🔒 Immutable icon on the release page:
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | ||
|
|
||
| - name: Run pre-commit checks | ||
| uses: ccao-data/actions/pre-commit@main |
There was a problem hiding this comment.
We control this action, so we don't need to pin it to a specific release.
There was a problem hiding this comment.
Makes sense. I spent a really long time trying to figure this out until I realized this comment points to line 16, not line 13 🤦♂️
wagnerlmichael
left a comment
There was a problem hiding this comment.
Awesome. Sorry evil hackers!
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | ||
|
|
||
| - name: Run pre-commit checks | ||
| uses: ccao-data/actions/pre-commit@main |
There was a problem hiding this comment.
Makes sense. I spent a really long time trying to figure this out until I realized this comment points to line 16, not line 13 🤦♂️
This PR upgrades all of our third-party GitHub Actions to ensure they are compatible with the upcoming Node 20 deprecation.
While we're at it, we also switch all of our references to third-party actions to point to immutable releases, so as to protect ourselves from the the ongoing scourge of supply chain attacks against third-party actions. If an action repo is using immutable releases, we pin to a specific immutable release; otherwise, we pin to the commit hash for the latest release of that action.
Test workflows to confirm these upgrades don't break anything:
pre-commit: https://github.com/ccao-data/homeval/actions/runs/26239715613/job/77222477440generate-homeval: https://github.com/ccao-data/homeval/actions/runs/26239864563Connects https://github.com/ccao-data/aws-infrastructure/issues/59.