Repository navigation
No behaviour change. Same image bytes as v2.7.1, referenced immutably.
v2.7.1 pinned the runtime image by tag:
image: 'docker://ghcr.io/dnyoussef/guardspine-code-action:2.7.1'
A registry tag is mutable — re-pushing 2.7.1 would silently change what every consumer pinned to @v2.7.1 executes, while the Dockerfile one directory away digest-pins its own base image. Holding our own artifact to a weaker standard than someone else's is an awkward asymmetry for a supply-chain governance product.
v2.7.2 pins by digest:
image: 'docker://ghcr.io/dnyoussef/guardspine-code-action@sha256:4b978fb4...'
action.yml is not copied into the image, so this changes the reference, not the artifact — v2.7.2 runs the exact bytes already built and published for v2.7.1.
Use @v2
A v2 tag now exists and points here. Before this, only v2.7.0 and v2.7.1 existed, so uses: ...@v2 failed to resolve for anyone following the usual major-version convention — and every documented example still said DNYoussef/codeguard-action@v1, which resolves to the genuine v1.0.5 lineage and installs years-old code without erroring.
- uses: DNYoussef/guardspine-code-action@v2Pin @v2.7.2 instead where you need byte reproducibility.
v2.7.0 remains superseded — it was tagged off main, where action.yml carries image: 'Dockerfile', so it rebuilds the container on every run instead of pulling the published image.