Bump golang & github action packages - #184
Conversation
📝 WalkthroughWalkthroughBumps the Go toolchain from 1.25.7/1.26.0 to 1.25.11/1.26.4 in the Dockerfile and CI matrix, and upgrades GitHub Actions references across all four workflow files: ChangesCI/CD Toolchain and Action Version Bumps
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~5 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/push.yaml:
- Line 25: Replace all mutable GitHub Action version tags with pinned full
commit SHAs across all workflow files to strengthen supply-chain security. In
`.github/workflows/push.yaml`, replace `actions/setup-go@v6` at line 25,
`actions/checkout@v6` at line 30, and `actions/upload-artifact@v7` at lines 64
and 71 with their respective commit SHAs. In `.github/workflows/release.yaml`,
replace `actions/checkout@v6` at line 18, `actions/setup-go@v6` at line 21, and
`softprops/action-gh-release@v3` at line 64 with commit SHAs. In
`.github/workflows/codeql.yaml`, replace `actions/checkout@v6` at line 31 with
its commit SHA. In `.github/workflows/docker.yaml`, replace
`actions/checkout@v6` at line 22, `docker/metadata-action@v6` at line 26,
`docker/setup-qemu-action@v4` at line 37, `docker/setup-buildx-action@v4` at
line 40, `docker/login-action@v4` at line 43, and `docker/build-push-action@v7`
at lines 56 and 69 with their respective commit SHAs. Look up the correct full
commit SHA for each action version from GitHub and update all references.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: f1b4ea7d-221f-4768-9c24-6c04b42f7f36
📒 Files selected for processing (5)
.github/workflows/codeql.yaml.github/workflows/docker.yaml.github/workflows/push.yaml.github/workflows/release.yamlDockerfile
📜 Review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
- GitHub Check: Build and Test (ubuntu-22.04, 1.26.4, linux, amd64)
- GitHub Check: Analyze (go)
- GitHub Check: Build and Test (ubuntu-22.04, 1.25.11, linux, arm64)
- GitHub Check: Build and Test (ubuntu-22.04, 1.25.11, linux, amd64)
- GitHub Check: Build and Test (ubuntu-22.04, 1.26.4, linux, arm64)
🧰 Additional context used
🪛 zizmor (1.25.2)
.github/workflows/release.yaml
[error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 21-21: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 21-21: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[error] 64-64: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[info] 64-64: action functionality is already included by the runner (superfluous-actions): use gh release in a script step
(superfluous-actions)
.github/workflows/push.yaml
[warning] 29-30: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 25-25: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 30-30: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 64-64: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 71-71: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
.github/workflows/docker.yaml
[error] 22-22: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 26-26: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 37-37: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 40-40: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 43-43: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 56-56: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 69-69: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
.github/workflows/codeql.yaml
[warning] 30-31: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 31-31: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🔇 Additional comments (2)
Dockerfile (1)
2-2: LGTM!.github/workflows/push.yaml (1)
29-31: ⚡ Quick winDisable checkout credential persistence for this job.
At Line 30, set
persist-credentials: falseonactions/checkoutunless a later step explicitly needs authenticated git operations. This reduces token exposure risk in a workflow that publishes artifacts.
[ suggest_recommended_refactor ]Source: Linters/SAST tools
Changes
Summary by CodeRabbit