Skip to content

Bump golang & github action packages - #184

Merged
notAreYouScared merged 1 commit into
pelican:mainfrom
QuintenQVD0:action-updates
Jun 22, 2026
Merged

notAreYouScared merged 1 commit into
pelican:mainfrom
QuintenQVD0:action-updates

Conversation

@QuintenQVD0

@QuintenQVD0 QuintenQVD0 commented Jun 15, 2026 •

Copy link
Copy Markdown
Contributor

Changes

  • Bump the Golang version for 1.25 and 1.26
  • Bump GitHub action packages

Summary by CodeRabbit

  • Chores
    • Upgraded GitHub Actions workflows to use newer versions of checkout, setup-go, Docker, and release actions for improved security and compatibility.
    • Updated Go build and runtime environment to the latest stable patch version for enhanced performance and stability.

@QuintenQVD0
QuintenQVD0 requested a review from a team as a code owner June 15, 2026 12:06
@coderabbitai

coderabbitai Bot commented Jun 15, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Bumps the Go toolchain from 1.25.7/1.26.0 to 1.25.11/1.26.4 in the Dockerfile and CI matrix, and upgrades GitHub Actions references across all four workflow files: actions/checkout to v6, actions/setup-go to v6, actions/upload-artifact to v7, Docker-related actions to their latest major versions, and softprops/action-gh-release from v1 to v3.

Changes

CI/CD Toolchain and Action Version Bumps

Layer / File(s) Summary
Go toolchain version updates
Dockerfile, .github/workflows/push.yaml, .github/workflows/release.yaml
Builder base image bumped to golang:1.25.11-alpine; CI matrix updated to Go 1.25.11/1.26.4; artifact upload conditions aligned to 1.25.11; go-version in release workflow updated to 1.25.11.
GitHub Actions and Docker action version bumps
.github/workflows/codeql.yaml, .github/workflows/docker.yaml, .github/workflows/push.yaml, .github/workflows/release.yaml
actions/checkout bumped to v6 across all workflows; docker/metadata-action to v6; docker/setup-qemu-action, docker/setup-buildx-action, docker/login-action to v4; docker/build-push-action to v7; softprops/action-gh-release from v1 to v3 with asset upload consolidated into files list.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~5 minutes

Possibly related PRs

  • pelican-dev/wings#172: Directly overlapping changes — modifies the same Go toolchain version fields in .github/workflows/push.yaml, .github/workflows/release.yaml, and Dockerfile.

Poem

🐇 Hop, hop, hooray for versions new,
The Go toolchain jumped from seven to eleven too!
Checkout v6, upload-artifact v7 in tow,
Docker actions freshened up, row by row.
The CI pipeline runs with a spring in its step,
This bunny approves — the stack is well-kept! 🌟

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'Bump golang & github action packages' accurately summarizes the main changes: updating Go versions (1.25.7→1.25.11 in Dockerfile and workflows) and GitHub action package versions across multiple workflow files.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/push.yaml:
- Line 25: Replace all mutable GitHub Action version tags with pinned full
commit SHAs across all workflow files to strengthen supply-chain security. In
`.github/workflows/push.yaml`, replace `actions/setup-go@v6` at line 25,
`actions/checkout@v6` at line 30, and `actions/upload-artifact@v7` at lines 64
and 71 with their respective commit SHAs. In `.github/workflows/release.yaml`,
replace `actions/checkout@v6` at line 18, `actions/setup-go@v6` at line 21, and
`softprops/action-gh-release@v3` at line 64 with commit SHAs. In
`.github/workflows/codeql.yaml`, replace `actions/checkout@v6` at line 31 with
its commit SHA. In `.github/workflows/docker.yaml`, replace
`actions/checkout@v6` at line 22, `docker/metadata-action@v6` at line 26,
`docker/setup-qemu-action@v4` at line 37, `docker/setup-buildx-action@v4` at
line 40, `docker/login-action@v4` at line 43, and `docker/build-push-action@v7`
at lines 56 and 69 with their respective commit SHAs. Look up the correct full
commit SHA for each action version from GitHub and update all references.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: f1b4ea7d-221f-4768-9c24-6c04b42f7f36

📥 Commits

Reviewing files that changed from the base of the PR and between a0306eb and 00e49d6.

📒 Files selected for processing (5)
  • .github/workflows/codeql.yaml
  • .github/workflows/docker.yaml
  • .github/workflows/push.yaml
  • .github/workflows/release.yaml
  • Dockerfile
📜 Review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build and Test (ubuntu-22.04, 1.26.4, linux, amd64)
  • GitHub Check: Analyze (go)
  • GitHub Check: Build and Test (ubuntu-22.04, 1.25.11, linux, arm64)
  • GitHub Check: Build and Test (ubuntu-22.04, 1.25.11, linux, amd64)
  • GitHub Check: Build and Test (ubuntu-22.04, 1.26.4, linux, arm64)
🧰 Additional context used
🪛 zizmor (1.25.2)
.github/workflows/release.yaml

[error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 21-21: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 21-21: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default

(cache-poisoning)


[error] 64-64: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[info] 64-64: action functionality is already included by the runner (superfluous-actions): use gh release in a script step

(superfluous-actions)

.github/workflows/push.yaml

[warning] 29-30: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 25-25: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 30-30: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 64-64: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 71-71: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

.github/workflows/docker.yaml

[error] 22-22: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 26-26: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 37-37: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 40-40: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 43-43: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 56-56: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 69-69: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

.github/workflows/codeql.yaml

[warning] 30-31: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 31-31: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🔇 Additional comments (2)
Dockerfile (1)

2-2: LGTM!

.github/workflows/push.yaml (1)

29-31: ⚡ Quick win

Disable checkout credential persistence for this job.

At Line 30, set persist-credentials: false on actions/checkout unless a later step explicitly needs authenticated git operations. This reduces token exposure risk in a workflow that publishes artifacts.
[ suggest_recommended_refactor ]

Source: Linters/SAST tools

Comment thread .github/workflows/push.yaml
@notAreYouScared
notAreYouScared merged commit c51b458 into pelican:main Jun 22, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants