Skip to content

ci: pin third-party actions to commit SHAs - #4051

Merged
B4nan merged 1 commit into
masterfrom
claude/crawlee-test-failure-d099c0
Aug 20, 2026
Merged

B4nan merged 1 commit into
masterfrom
claude/crawlee-test-failure-d099c0

Conversation

@B4nan

@B4nan B4nan commented Aug 19, 2026

Copy link
Copy Markdown
Member

This pins every third-party action in our workflows to a full commit SHA, keeping the resolved version tag as a trailing comment. Renovate understands that convention and updates the SHA and comment together.

The trigger: yesterday the v11 tag of EndBug/add-and-commit moved to the broken v11.1.0 release, whose action.yml fails to load (Unrecognized named-value: 'github'), which killed our publish workflow (failed run). With SHA pins, a tag moving under us, by accident or by compromise, can't break or hijack CI anymore. EndBug/add-and-commit is pinned to v11.0.0, the last working release; the upstream fix is pending in EndBug/add-and-commit#783.

Own-org references (apify/workflows, apify/actions, apify/setup-apify-cli-action) stay on floating refs on purpose, since we control those repos.

Floating tags can move to broken or malicious commits, as happened with
EndBug/add-and-commit v11 (its v11.1.0 release fails to load, breaking
every workflow that references it). Pin all third-party actions to full
commit SHAs with the resolved version tag in a trailing comment. Own-org
(apify/*) references stay on floating refs intentionally.

EndBug/add-and-commit is pinned to v11.0.0, as the current v11 tag
points at the broken v11.1.0 release.
@B4nan B4nan added t-tooling Issues with this label are in the ownership of the tooling team. adhoc Ad-hoc unplanned task added during the sprint. labels Aug 19, 2026
@github-actions github-actions Bot added this to the 147th sprint - Tooling team milestone Aug 19, 2026
@B4nan
B4nan requested a review from janbuchar August 19, 2026 14:14
This was referenced Aug 20, 2026
@B4nan
B4nan requested a review from barjin August 20, 2026 11:28
B4nan added a commit to apify/docusaurus-plugin-typedoc-api that referenced this pull request Aug 20, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/apify-docs that referenced this pull request Aug 20, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/apify-eslint-config that referenced this pull request Aug 20, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/apify-oxlint-config that referenced this pull request Aug 20, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/apify-tsconfig that referenced this pull request Aug 20, 2026
Floating tags can move to broken or malicious commits, as happened with
EndBug/add-and-commit v11 (see apify/crawlee#4051). Pin all third-party
actions to full commit SHAs with the resolved version tag in a trailing
comment. Own-org (apify/*) references stay on floating refs.
B4nan added a commit to apify/apify-storage-local-js that referenced this pull request Aug 20, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/camoufox-js that referenced this pull request Aug 20, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/fingerprint-suite that referenced this pull request Aug 20, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/apify-shared-js that referenced this pull request Aug 20, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/apify-client-js that referenced this pull request Aug 20, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/apify-sdk-js that referenced this pull request Aug 20, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
@B4nan
B4nan merged commit d57a413 into master Aug 20, 2026
10 checks passed
@B4nan
B4nan deleted the claude/crawlee-test-failure-d099c0 branch August 20, 2026 12:30
B4nan added a commit to apify/release-pr-action that referenced this pull request Aug 20, 2026
Floating tags can move to broken or malicious commits, as happened with
EndBug/add-and-commit v11 (see apify/crawlee#4051). Pin all third-party
actions to full commit SHAs with the resolved version tag in a trailing
comment. Own-org (apify/*) references stay on floating refs.
B4nan added a commit to apify/pull-request-toolkit-action that referenced this pull request Aug 20, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/workflows that referenced this pull request Aug 20, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/proxy-chain that referenced this pull request Aug 20, 2026
Floating tags can move to broken or malicious commits, as happened with
EndBug/add-and-commit v11 (see apify/crawlee#4051). Pin all third-party
actions to full commit SHAs with the resolved version tag in a trailing
comment. Own-org (apify/*) references stay on floating refs.
B4nan added a commit to apify/crawlee-python that referenced this pull request Aug 21, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/apify-client-python that referenced this pull request Aug 21, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/apify-sdk-python that referenced this pull request Aug 21, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/got-scraping that referenced this pull request Aug 26, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/actor-templates that referenced this pull request Aug 31, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
B4nan added a commit to apify/apify-cli that referenced this pull request Sep 3, 2026
This pins every third-party action in the workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

Same change as apify/crawlee#4051, rolled out team-wide. The trigger was
the `v11` tag of `EndBug/add-and-commit` moving to a broken release that
failed to load and killed the crawlee publish workflow. With SHA pins, a
tag moving under us, by accident or by compromise, can't break or hijack
CI anymore. Where `EndBug/add-and-commit` is used, it's pinned to
v11.0.0, the last working release.

Own-org references (`apify/*`) stay on floating refs on purpose, since
we control those repos.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

adhoc Ad-hoc unplanned task added during the sprint. t-tooling Issues with this label are in the ownership of the tooling team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants