Skip to content

ci: pin actions to full commit SHAs - #113

Closed
eepifanova wants to merge 1 commit into
mainfrom
pin-actions
Closed

ci: pin actions to full commit SHAs#113
eepifanova wants to merge 1 commit into
mainfrom
pin-actions

Conversation

@eepifanova

Copy link
Copy Markdown

Summary

Pin action refs from mutable tags to full commit SHAs to prevent supply-chain attacks.

Changes

Action Before After
actions/checkout v6 de0fac2e...

Applied to: alpine.yml, ubuntu.yml

No behavioral changes — supply-chain hardening only.

- actions/checkout: v6 -> de0fac2e...

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@eepifanova
eepifanova requested a review from p-pautov March 27, 2026 15:22
@p-pautov

Copy link
Copy Markdown
Contributor

That could make sense for 3rd-party actions, but not so much for GitHub-provided actions from "actions/*". By using major version tag, we automatically get all the minor updates currently.

@eepifanova

Copy link
Copy Markdown
Author

That could make sense for 3rd-party actions, but not so much for GitHub-provided actions from "actions/*". By using major version tag, we automatically get all the minor updates currently.

It's not a question of trust. It's a way to prevent supply-chain attack so the new malicious code will not be able to affect repos using these actions.

@p-pautov

Copy link
Copy Markdown
Contributor

That could make sense for 3rd-party actions, but not so much for GitHub-provided actions from "actions/*". By using major version tag, we automatically get all the minor updates currently.

It's not a question of trust. It's a way to prevent supply-chain attack so the new malicious code will not be able to affect repos using these actions.

It is a question of trust in action provider and its security processes. In case of "actions/*" it's GitHub, which we have to trust if host code here.

@thresheek

Copy link
Copy Markdown
Member

You overestimate the quality of processes on GitHub. We do use their infra to spawn and run checks, but who owns actions/* is an entirely different matter since the teams are not connected. There is no guarantee they are under the same strict control security-wise, or else.

I'm just saying that it's better to be safe than sorry. We can always bump the ids if we see issues.

@p-pautov

p-pautov commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

You overestimate the quality of processes on GitHub. We do use their infra to spawn and run checks, but who owns actions/* is an entirely different matter since the teams are not connected. There is no guarantee they are under the same strict control security-wise, or else.

I'm just saying that it's better to be safe than sorry. We can always bump the ids if we see issues.

I don't see a reason to assume that "actions team" uses lesser security controls, it could be the opposite.

And, as was noted above, with current approach we are getting bugfixes automatically, which can include security fixes as well.

Overall, the change seems unnecessary.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants