Skip to content

chore(ci): pin some lingering actions by hash - #15016

Merged
woodruffw merged 1 commit into
mainfrom
ww/ci-fixes
Aug 1, 2025
Merged

chore(ci): pin some lingering actions by hash#15016
woodruffw merged 1 commit into
mainfrom
ww/ci-fixes

Conversation

@woodruffw

Copy link
Copy Markdown
Member

This is the first of several burndown PRs for CI.

I did this automatically with pinact run -v
and then cross-checked with zizmor's
impostor commit audit.

Summary

This takes our remaining ref-pinned GitHub Actions usage and hash-pins them. In other words, @v1 becomes @feedfacefeedface....

Doing this makes our action usage de facto immutable, at least at the repository state level -- the actions themselves might still be non-idempotent/hermetic/reproducible, but the repository state itself can't change like it could before with a tag overwrite.

Test Plan

This should be a non-functional change. However, the only way to really confirm that is to run the CI and see what happens 🙂

I did this automatically with `pinact run -v`
and then cross-checked with `zizmor`'s
impostor commit audit.

Signed-off-by: William Woodruff <william@astral.sh>
@woodruffw
woodruffw requested review from konstin and zanieb August 1, 2025 18:47
@woodruffw woodruffw self-assigned this Aug 1, 2025

@zanieb zanieb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@zanieb zanieb added the internal A refactor or improvement that is not user-facing label Aug 1, 2025
@woodruffw
woodruffw temporarily deployed to uv-test-registries August 1, 2025 18:50 — with GitHub Actions Inactive
@woodruffw
woodruffw temporarily deployed to uv-test-publish August 1, 2025 18:50 — with GitHub Actions Inactive
@woodruffw
woodruffw merged commit 0b3c32c into main Aug 1, 2025
111 checks passed
@woodruffw
woodruffw deleted the ww/ci-fixes branch August 1, 2025 19:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

internal A refactor or improvement that is not user-facing

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants