From fcd6a6cb4f812f7b52e57c6287b34b7bad5639ed Mon Sep 17 00:00:00 2001 From: samuelburnham <45365069+samuelburnham@users.noreply.github.com> Date: Thu, 1 Oct 2026 13:15:58 -0400 Subject: [PATCH] ci: pin actions to commit SHAs and lint workflows Every third-party `uses:` now carries a full commit SHA with a version comment, the form Dependabot reads to keep the pins fresh. lean-update's `dev` and the shared ci-workflows actions on `main` are branch refs with no tag to pin to; `.github/pinact.yaml` exempts them and `.github/zizmor.yml` gives them a ref-pin policy. A `lints` job calls ci-workflows' lint-workflows action (actionlint, shellcheck over composite action scripts, pinact check and verify, zizmor). Getting zizmor clean: every checkout sets `persist-credentials: false` (lean-update pushes through its own token input, not the checkout's git credentials), the Nix installer reads `github.token`, and Dependabot gets the 7-day cooldown zizmor requires. --- .github/dependabot.yml | 2 ++ .github/pinact.yaml | 9 +++++++++ .github/workflows/ci.yml | 19 ++++++++++++++++--- .github/workflows/nix.yml | 22 +++++++++++++--------- .github/workflows/update.yml | 5 +++-- .github/zizmor.yml | 8 ++++++++ 6 files changed, 51 insertions(+), 14 deletions(-) create mode 100644 .github/pinact.yaml create mode 100644 .github/zizmor.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml index d15c975..cfd3783 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,6 +4,8 @@ updates: directory: "/" schedule: interval: "weekly" + cooldown: + default-days: 7 groups: actions: patterns: diff --git a/.github/pinact.yaml b/.github/pinact.yaml new file mode 100644 index 0000000..75ff053 --- /dev/null +++ b/.github/pinact.yaml @@ -0,0 +1,9 @@ +version: 3 +rules: + # Branch refs that must keep tracking their branch: there is no stable tag + # to pin to. lean-update's `dev` carries the fork's features, and the shared + # ci-workflows actions are consumed from `main`. + - ignore: true + conditions: + - expr: ActionName == "argumentcomputer/lean-update" + - expr: ActionName matches "^argumentcomputer/ci-workflows/" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7bda0e7..48aaa9e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -25,8 +25,10 @@ jobs: runs-on: runs-on=${{ github.run_id }}-build-${{ github.run_attempt }}/cpu=8/family=r7i+r8i+r7a+r8a/image=ubuntu26-full-x64/volume=100gb/sticky=ci-build:50gb timeout-minutes: 60 steps: - - uses: actions/checkout@v7 - - uses: runs-on/action@v2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: runs-on/action@dfae4d98c5537a0dc7bbb7e6b9211f30ba240f6d # v2.4.0 with: sticky_cache: | custom,path=.lake @@ -38,7 +40,7 @@ jobs: # the frontier `sorry`s are annotated at their declarations, so they no # longer count. `Lean4Lean.Experimental` is not a default target. - name: Build - uses: leanprover/lean-action@v1 + uses: leanprover/lean-action@50fcf42d2e460296f1a34b402e990d1b24f8b596 # v1.6.0 with: build-args: --wfail use-github-cache: false @@ -79,3 +81,14 @@ jobs: # support loose bound variables" (digama0/lean4lean#17). - name: Recheck Init.System.IO and its imports from scratch run: lake exe lean4lean --fresh Init.System.IO + + lints: + name: Lint workflows + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + # actionlint, shellcheck over composite action scripts, pinact (actions + # must be SHA-pinned with a matching version comment) and zizmor + - uses: argumentcomputer/ci-workflows/.github/actions/lint-workflows@main diff --git a/.github/workflows/nix.yml b/.github/workflows/nix.yml index 4673c84..fde0905 100644 --- a/.github/workflows/nix.yml +++ b/.github/workflows/nix.yml @@ -23,12 +23,14 @@ jobs: # /nix lives on the root volume; Cachix is the binary cache, so no sticky disk runs-on: runs-on=${{ github.run_id }}-nix-test-${{ github.run_attempt }}/cpu=8/family=r7i+r8i+r7a+r8a/image=ubuntu26-full-x64/volume=100gb steps: - - uses: actions/checkout@v7 - - uses: cachix/install-nix-action@v31 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 with: nix_path: nixpkgs=channel:nixos-unstable - github_access_token: ${{ secrets.GITHUB_TOKEN }} - - uses: cachix/cachix-action@v17 + github_access_token: ${{ github.token }} + - uses: cachix/cachix-action@38b082610b782e7e93e209c35fd730d399dee866 # v17 with: name: argumentcomputer authToken: ${{ secrets.CACHIX_AUTH_TOKEN }} @@ -47,16 +49,18 @@ jobs: # on a sticky disk like ci.yml's runs-on: runs-on=${{ github.run_id }}-nix-devshell-${{ github.run_attempt }}/cpu=8/family=r7i+r8i+r7a+r8a/image=ubuntu26-full-x64/volume=100gb/sticky=nix-devshell:50gb steps: - - uses: actions/checkout@v7 - - uses: runs-on/action@v2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: runs-on/action@dfae4d98c5537a0dc7bbb7e6b9211f30ba240f6d # v2.4.0 with: sticky_cache: | custom,path=.lake - - uses: cachix/install-nix-action@v31 + - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 with: nix_path: nixpkgs=channel:nixos-unstable - github_access_token: ${{ secrets.GITHUB_TOKEN }} - - uses: cachix/cachix-action@v17 + github_access_token: ${{ github.token }} + - uses: cachix/cachix-action@38b082610b782e7e93e209c35fd730d399dee866 # v17 with: name: argumentcomputer authToken: ${{ secrets.CACHIX_AUTH_TOKEN }} diff --git a/.github/workflows/update.yml b/.github/workflows/update.yml index b0c37a3..795de83 100644 --- a/.github/workflows/update.yml +++ b/.github/workflows/update.yml @@ -17,12 +17,13 @@ jobs: # create-pull-request takes its base from the checked-out branch, and the # action passes no `base` of its own, so this is what points the update PR # at `main`, the default branch. - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: ref: main + persist-credentials: false # `update_lean4_nix` below runs `nix flake update` - - uses: cachix/install-nix-action@v31 + - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 with: github_access_token: ${{ github.token }} diff --git a/.github/zizmor.yml b/.github/zizmor.yml new file mode 100644 index 0000000..576392f --- /dev/null +++ b/.github/zizmor.yml @@ -0,0 +1,8 @@ +rules: + unpinned-uses: + config: + policies: + # Branch-tracking refs allowed by .github/pinact.yaml + "argumentcomputer/lean-update": ref-pin + "argumentcomputer/ci-workflows/*": ref-pin + "*": hash-pin