Skip to content

chore(ci): pin third-party actions to commit SHAs in the 11 workflows that still floated @v7 - #1621

Merged
erni-a merged 2 commits into
mainfrom
chore/pin-actions-sha
Sep 20, 2026
Merged

erni-a merged 2 commits into
mainfrom
chore/pin-actions-sha

Conversation

@erni-a

@erni-a erni-a commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Summary

Closes #1399.

Replaces the 23 floating @v7 references across 11 workflows with the full commit SHA plus version comment that ci.yml, codeql.yml, dco.yml, labels-sync.yml, legacy-name-ratchet.yml, publish-docker.yml and security-scan.yml already use. Same SHAs as those files, so every workflow is on one version per action:

Action SHA Version
actions/checkout 3d3c42e5aac5ba805825da76410c181273ba90b1 v7.0.1
actions/setup-node 820762786026740c76f36085b0efc47a31fe5020 v7.0.0
actions/setup-python 5fda3b95a4ea91299a34e894583c3862153e4b97 v7.0.0

Seven of the eleven are the publish-* workflows that hold npm and PyPI credentials, which is where a retagged upstream tag matters most. Dependabot's github-actions entry understands SHA pins, so version updates keep arriving.

Related Issue

Closes #1399. #1400 (persist-credentials: false) landed first in #1481, so there is no textual conflict left.

Type of Change

  • Other: CI hardening, config only

How Has This Been Tested?

  • grep -rn "uses: [a-zA-Z].*@v[0-9]" .github/workflows/ prints nothing.
  • Every workflow file still parses as YAML.
  • After the change the repo has exactly three distinct actions/* pins: 24× checkout, 7× setup-node, 5× setup-python.
  • No behaviour change: same action versions the tags resolved to today.

Checklist

  • I have read CONTRIBUTING.md
  • Tests: config-only change, verification is the grep above and the workflows running on this PR
  • Every commit is signed off (DCO)
  • Not user-facing, no CHANGELOG entry

…t SHAs in the 11 workflows that still floated @v7

Closes #1399.

Seven of the eleven are the publish workflows that hold npm and PyPI
credentials, so they are where a retagged upstream action matters most.
Reuses the exact SHAs ci.yml and legacy-name-ratchet.yml already pin, so
every workflow lands on one version per action:

  actions/checkout      3d3c42e5aac5ba805825da76410c181273ba90b1  v7.0.1
  actions/setup-node    820762786026740c76f36085b0efc47a31fe5020  v7.0.0
  actions/setup-python  5fda3b95a4ea91299a34e894583c3862153e4b97  v7.0.0

Dependabot's github-actions entry understands SHA pins, so updates keep
flowing. Verified: grep -rn 'uses: [a-zA-Z].*@v[0-9]' .github/workflows/
prints nothing.

Signed-off-by: erni <erni@caura.ai>
@erni-a
erni-a requested a review from a team as a code owner September 19, 2026 15:04
@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'erni-a' is not a public member of the 'caura-ai' org

@github-actions

Copy link
Copy Markdown
Contributor

Claude Code Review — skipped: PR author 'erni-a' is not a public member of the 'caura-ai' org

@erni-a
erni-a merged commit b8dbfe8 into main Sep 20, 2026
16 checks passed
@erni-a
erni-a deleted the chore/pin-actions-sha branch September 20, 2026 04:46
erni-a added a commit that referenced this pull request Sep 20, 2026
…client CI (#1622)

## Summary

Closes #1403.

The Python client CI runs ruff before pytest; the TypeScript client CI
ran only `tsc` and `node --test`, so nothing caught formatting drift.
This takes the smaller of the two routes the issue offers, **Prettier
`--check`, not ESLint**: one dev dependency, one config key, and the
source is about 300 lines, which does not justify a rule set to
maintain. ESLint stays available as a later step if the client grows.

- `clients/typescript/.prettierrc`: `printWidth: 110`, matching the
`line-length = 110` the repo's ruff config already uses for Python, so
both clients wrap at the same column. Everything else is Prettier's
default.
- `package.json`: `prettier ^3.6` as a devDependency (pinned through the
lockfile, so CI and local runs agree), plus `lint` and `format` scripts
so contributors run exactly what CI runs.
- `client-typescript-ci.yml`: a `Lint (prettier)` step before `Build +
test`, mirroring the Python workflow's ordering.
- `src/`: the reformat the first run reports. No logic change.

`npm install` and the Node-20-only matrix are left alone; #973 tracks
them. Stacked on #1621 (same workflow file); merge that first and this
rebases clean.

## Related Issue

Closes #1403.

## Type of Change

- [x] Other: CI gate for the TypeScript client

## How Has This Been Tested?

- `npm run lint` fails on `main`'s source and passes after the reformat.
- `npm test`: tsc clean, 31/31 pass on Node 20.
- `.prettierrc` is not in the package `files` list, so the published
tarball is unchanged.
- The workflow is path-scoped to `clients/typescript/**`, so this PR
triggers it and the new step is visible in the job log.

## Checklist

- [x] I have read CONTRIBUTING.md
- [x] Tests: existing suite covers the reformatted code; the lint step
is the new gate
- [x] Every commit is signed off (DCO)
- [x] Not user-facing, no CHANGELOG entry

Signed-off-by: erni <erni@caura.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore(ci): pin third-party actions to commit SHAs in the 11 workflows that still float @v7

2 participants