From 916fff132abb1803c6c60f398688d46ee261567f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Martin=20Ad=C3=A1mek?= Date: Thu, 20 Aug 2026 13:07:52 +0200 Subject: [PATCH] ci: pin third-party actions to commit SHAs Floating tags can move to broken or malicious commits, as happened with EndBug/add-and-commit v11 (see apify/crawlee#4051). Pin all third-party actions to full commit SHAs with the resolved version tag in a trailing comment. Own-org (apify/*) references stay on floating refs. --- .github/workflows/publish_to_npm.yaml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/publish_to_npm.yaml b/.github/workflows/publish_to_npm.yaml index a879fe2..de97bac 100644 --- a/.github/workflows/publish_to_npm.yaml +++ b/.github/workflows/publish_to_npm.yaml @@ -32,13 +32,13 @@ jobs: exit 1 - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 with: token: ${{ secrets.APIFY_SERVICE_ACCOUNT_GITHUB_TOKEN }} fetch-depth: 0 # Fetch all history for tags - name: Setup Node.js - uses: actions/setup-node@v6 + uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0 with: node-version: 24 @@ -52,7 +52,7 @@ jobs: - name: Generate full changelog id: git-cliff - uses: orhun/git-cliff-action@v4 + uses: orhun/git-cliff-action@f50e11560dce63f7c33227798f90b924471a88b5 # v4.8.0 with: args: --tag "v${{ steps.get_version.outputs.VERSION }}" env: @@ -84,7 +84,7 @@ jobs: # Generate release notes only from the current version - name: Generate changelog for release notes id: git-cliff-release-notes - uses: orhun/git-cliff-action@v4 + uses: orhun/git-cliff-action@f50e11560dce63f7c33227798f90b924471a88b5 # v4.8.0 with: args: --tag "v${{ steps.get_version.outputs.VERSION }}" --current --strip all @@ -104,7 +104,7 @@ jobs: } >> $GITHUB_OUTPUT - name: Create release - uses: softprops/action-gh-release@v2 + uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2.6.2 with: tag_name: "v${{ steps.get_version.outputs.VERSION }}" name: "v${{ steps.get_version.outputs.VERSION }}"