Skip to content

ci: pin actions to commit SHAs and lint workflows - #56

Merged
samuelburnham merged 1 commit into
mainfrom
ci/pin-actions
Oct 1, 2026
Merged

samuelburnham merged 1 commit into
mainfrom
ci/pin-actions

Conversation

@samuelburnham

Copy link
Copy Markdown
Member

Every third-party uses: now carries a full commit SHA with a version comment, the form Dependabot reads to keep the pins fresh. lean-update's dev and the shared ci-workflows actions on main are branch refs with no tag to pin to; .github/pinact.yaml exempts them and .github/zizmor.yml gives them a ref-pin policy.

A lints job calls ci-workflows' lint-workflows action (actionlint, shellcheck over composite action scripts, pinact check and verify, zizmor). Getting zizmor clean: the CI workflow declares contents: read instead of inheriting the repository default, every checkout sets persist-credentials: false (lean-update pushes through its own token input, not the checkout's git credentials), the Nix installer reads github.token, and Dependabot gets the 7-day cooldown zizmor requires.

Dependabot now also covers the Rust crate under rust/, which had no cargo ecosystem entry. The valgrind job restored a cache from test/.lake keyed on a test/lake-manifest.json that does not exist, so it always rebuilt from scratch; it now restores the root .lake under the key lean-action saves in the lean-test job.

Every third-party `uses:` now carries a full commit SHA with a version
comment, the form Dependabot reads to keep the pins fresh. lean-update's
`dev` and the shared ci-workflows actions on `main` are branch refs with no
tag to pin to; `.github/pinact.yaml` exempts them and `.github/zizmor.yml`
gives them a ref-pin policy.

A `lints` job calls ci-workflows' lint-workflows action (actionlint,
shellcheck over composite action scripts, pinact check and verify, zizmor).
Getting zizmor clean: the CI workflow declares `contents: read` instead of
inheriting the repository default, every checkout sets
`persist-credentials: false` (lean-update pushes through its own token
input, not the checkout's git credentials), the Nix installer reads
`github.token`, and Dependabot gets the 7-day cooldown zizmor requires.

Dependabot now also covers the Rust crate under `rust/`, which had no cargo
ecosystem entry. The valgrind job restored a cache from `test/.lake` keyed
on a `test/lake-manifest.json` that does not exist, so it always rebuilt
from scratch; it now restores the root `.lake` under the key lean-action
saves in the lean-test job.
@samuelburnham
samuelburnham enabled auto-merge (squash) October 1, 2026 17:06
@samuelburnham
samuelburnham merged commit 3f8b805 into main Oct 1, 2026
4 checks passed
@samuelburnham
samuelburnham deleted the ci/pin-actions branch October 1, 2026 17:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants