Skip to content

ci: pin remaining GitHub Actions to immutable commits - #82

Merged
iHildy merged 1 commit into
mainfrom
ian/pin-github-actions-security-scan
Sep 23, 2026
Merged

iHildy merged 1 commit into
mainfrom
ian/pin-github-actions-security-scan

Conversation

@iHildy

@iHildy iHildy commented Sep 23, 2026

Copy link
Copy Markdown
Owner

Summary

Pin the three remaining GitHub Actions that used movable major-version tags to the commits those tags resolved to during the audit:

  • actions/checkout@v4 to 11d5960a326750d5838078e36cf38b85af677262
  • oven-sh/setup-bun@v2 to 0c5077e51419868618aeaa5fe8019c62421857d6
  • amannn/action-semantic-pull-request@v5 to e32d7e603df1aa1ba07e981f2a23455dee596825

This addresses the three unpinned action findings in the advisory scan on catalog PR #429. The four high-severity secret findings appear to be test fixtures in src/sync/config.test.ts, src/sync/apply.test.ts, src/sync/mcp-secrets.test.ts, and src/index.test.ts. No provider token pattern was found in the tracked source. SECURITY.md and Dependabot findings are separate low-severity repository maintenance items.

Verification

  • Resolved each tag through the corresponding repository's GitHub Git ref API before pinning.
  • bun run check passed without changes.
  • bun test passed, 196 tests.
  • bun run build passed.
  • git diff --check passed.

The plugin runtime is unchanged, so the isolated sync E2E was not rerun for this workflow-only update.

@iHildy
iHildy merged commit 2cc7bed into main Sep 23, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant