Skip to content

chore: pin GitHub Actions to commit SHAs - #4130

Open
BGos87 wants to merge 1 commit into
mainfrom
chore/pin-github-actions-20260923
Open

BGos87 wants to merge 1 commit into
mainfrom
chore/pin-github-actions-20260923

Conversation

@BGos87

@BGos87 BGos87 commented Sep 23, 2026 •

Copy link
Copy Markdown

Summary

Pin every uses: ref in .github/workflows/ (and any composite action
files) to a full 40-character commit SHA, with the original tag
preserved as a # vX comment.

Why

Tags and branches are mutable, so a compromised action can replace what
runs in our pipelines without changing the tag we reference. Pinning to
a SHA closes that supply-chain vector. See GitHub's hardening guide:
https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions.

Deadline

TechOps is enforcing SHA-pinned GitHub Actions across the org.
Merging this PR brings the repo into compliance; workflows that still
reference mutable tags or branches may be blocked from running.

How

Generated mechanically with pinact run.
No version bumps were applied (strict pin); follow-up upgrades can come
from Renovate or a separate pinact run -u PR.

Test plan

  • CI green on this branch

Note

Low Risk
Workflow-only ref changes that lock the same action commits already implied by the prior tags; no application or publish logic changes.

Overview
Replaces mutable action tags (e.g. @v3, @v7) with immutable 40-character commit SHAs across all .github/workflows/ files, keeping the original tag in a # vX comment for readability.

Coverage spans CI (build/lint/test, coverage, e2e, platform tests), main orchestration (merge queue, security scan, release detection), and deployment paths (NPM publish, GitHub Pages, AWS environment publish, preview builds, @metamaskbot update-pr). Third-party and MetaMask actions (actions/checkout, artifact upload/download, action-checkout-and-setup, action-npm-publish, github-tools/get-token, etc.) are pinned the same way; no action version upgrades—only ref hardening for org compliance.

Reviewed by Cursor Bugbot for commit f604549. Bugbot is set up for automated code reviews on this repo. Configure here.

Pin every `uses:` ref in .github/workflows and composite actions to a
full 40-character commit SHA, with the original tag preserved as a
comment, e.g.

    uses: actions/checkout@11bd719 # v4

Tags and branches are mutable; commit SHAs are not. Pinning to a SHA
closes a supply-chain vector where a compromised action could replace
what runs in CI without changing the tag we reference.

Generated mechanically with `pinact run`
(https://github.com/suzuki-shunsuke/pinact). No version bumps were
applied (strict pin).
@BGos87
BGos87 requested a review from a team as a code owner September 23, 2026 14:03
@codecov

codecov Bot commented Sep 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.60%. Comparing base (f42b562) to head (f604549).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #4130   +/-   ##
=======================================
  Coverage   98.60%   98.60%           
=======================================
  Files         429      429           
  Lines       12513    12513           
  Branches     1977     1977           
=======================================
  Hits        12338    12338           
  Misses        175      175           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant