Skip to content

Pin GitHub Actions to full-length commit SHAs - #1192

Merged
Jay Bosamiya (Microsoft) (jaybosamiya-ms) merged 1 commit into
microsoft:mainfrom
danfiedler-msft:danfiedler/pin-actions
Aug 19, 2026
Merged

Jay Bosamiya (Microsoft) (jaybosamiya-ms) merged 1 commit into
microsoft:mainfrom
danfiedler-msft:danfiedler/pin-actions

Conversation

@danfiedler-msft

@danfiedler-msft Dan Fiedler (danfiedler-msft) commented Aug 18, 2026 •

Copy link
Copy Markdown
Contributor

This PR pins GitHub Actions to full-length commit SHAs and adds a 7 day cooldown to Dependabot configuration for GitHub Actions. See more detail at https://aka.ms/action-pinning.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks Dan, the changes look good to me. As a heads up, I'll rewrite the PR description to shorten it before I merge it in, since that becomes part of the git history with the merge queues we use.

Sidenote: for future reference, quick script to validate the commit hashes:

grep -rhoP 'uses:\s*\K[\w.-]+/[\w.-]+@[0-9a-f]+\s*#\s*v?[\w.-]+' .github/workflows/ \
  | sed 's/#//' | sort -u \
  | while read -r ref tag; do
      repo=${ref%@*}; sha=${ref#*@}
      actual=$(gh api "repos/$repo/git/ref/tags/$tag" --jq '.object.sha' 2>/dev/null)
      typ=$(gh api "repos/$repo/git/ref/tags/$tag" --jq '.object.type' 2>/dev/null)
      [ "$typ" = tag ] && actual=$(gh api "repos/$repo/git/tags/$actual" --jq '.object.sha')
      if [ "$actual" = "$sha" ]; then echo "OK   $repo $tag"; else echo "BAD  $repo $tag: comment=$tag sha=$sha actual=$actual"; fi
    done

Merged via the queue into microsoft:main with commit 12aa111 Aug 19, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants