[Core feature request] Pinning action versions to commit hashes updateable by bots
@krzema12 arbeitet bereits daran.
Seit 27.4.2025.
Bewertung
Dieses Issue wurde noch nicht bewertet.
Beschreibung
What feature do you need?
By default, when using a binding provided by the bindings server, we refer by the major or full version. It can be a branch or a tag. While major version tags/branches change and it's expected, full versions shouldn't. However, technically nothing stops the action owner to hard-reset some full version branch/tag to point to a different commit, and no one will notice it.
That's why, as a part of security hardening, some workflow owners use full SHA-1 of commits they want to use for each action. It guarantees the action's code won't silently change.
Users of github-workflows-kt can already do it using _customVersion constructor argument:
UploadArtifact(
// ...
_customVersion = "actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11",
)
However, dependency updating bots cannot update such commit hashes.
In theory we could try allowing such format when specifying a dependency on an action:
@file:DependsOn("actions:checkout:b4ffde65f46336ab88eb53be808477a3936bae11")
but then, even if we make this commit hash be updated to the right value, there's no mechanism to keep the full version in the comment, like shown in the below example.
Do you have an example usage?
uses: 'actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11' # v4.1.1
Is there a workaround for not having this feature? If yes, please describe it.
No way to make the dependency updating bots work, just specifying the commit hash as version.
- Vorherrschende Sprache
- Kotlin
- Sterne
- 664
- Forks
- 30
- Ø Merge
- 4 T. 19 Std.
- Gemergte PRs (30 T.)
- 5
Beitragsleitfaden
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus typesafegithub/github-workflows-kt
-
bug
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 58/100
typesafegithub/github-workflows-kt#2389 · 7 Kommentare ·
-
bug
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 42/100
typesafegithub/github-workflows-kt#2368 · 1 Kommentar ·
-
problem
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 42/100
typesafegithub/github-workflows-kt#2348 · 2 Kommentare ·
-
operational
typesafegithub/github-workflows-kt#1884 · 1 zugewiesene Person ·
-
problem
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 30/100
typesafegithub/github-workflows-kt#1864 · 5 Kommentare ·
Alle Issues in typesafegithub/github-workflows-kt
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
-
Good First Issue
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
ankidroid/Anki-Android#21942 ·
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
libre-tube/LibreTube#8781 · 1 Kommentar ·
-
enhancement
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
MetrolistGroup/Metrolist#4396 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100