Skip to content

v2.7.2 - same artifact as v2.7.1, pinned by immutable digest

Latest

Choose a tag to compare

@DNYoussef DNYoussef released this 29 Jul 13:57
· 7 commits to main since this release

No behaviour change. Same image bytes as v2.7.1, referenced immutably.

v2.7.1 pinned the runtime image by tag:

image: 'docker://ghcr.io/dnyoussef/guardspine-code-action:2.7.1'

A registry tag is mutable — re-pushing 2.7.1 would silently change what every consumer pinned to @v2.7.1 executes, while the Dockerfile one directory away digest-pins its own base image. Holding our own artifact to a weaker standard than someone else's is an awkward asymmetry for a supply-chain governance product.

v2.7.2 pins by digest:

image: 'docker://ghcr.io/dnyoussef/guardspine-code-action@sha256:4b978fb4...'

action.yml is not copied into the image, so this changes the reference, not the artifact — v2.7.2 runs the exact bytes already built and published for v2.7.1.

Use @v2

A v2 tag now exists and points here. Before this, only v2.7.0 and v2.7.1 existed, so uses: ...@v2 failed to resolve for anyone following the usual major-version convention — and every documented example still said DNYoussef/codeguard-action@v1, which resolves to the genuine v1.0.5 lineage and installs years-old code without erroring.

- uses: DNYoussef/guardspine-code-action@v2

Pin @v2.7.2 instead where you need byte reproducibility.

v2.7.0 remains superseded — it was tagged off main, where action.yml carries image: 'Dockerfile', so it rebuilds the container on every run instead of pulling the published image.