ci: pin remaining actions/checkout refs to an immutable SHA - #11
Merged
Merged
Conversation
publish.yml and publish-features.yml still referenced actions/checkout by the mutable "v7" tag, while every other action in these workflows (and the checkout step in sonarqube.yml) is already pinned to a full commit SHA with a version comment. Bring these two in line with that convention: actions/checkout@3d3c42e is the commit for the current v7.0.1 release (verified against the actions/checkout releases page - no newer v7.x release exists), so this is a like-for-like pin, not a version bump. No other outdated or vulnerable pin was found in this pass: - Dockerfile base (mcr.microsoft.com/devcontainers/base:bookworm) is a floating tag on a Debian line supported through 2028, not a stale fixed version. - The traefik feature's install.sh pins the Docker image to the floating "traefik:v3.7" tag, which already resolves to v3.7.13 (released 2026-09-04) - the release that fixes the two Traefik CVEs disclosed against the 3.7 line this month (CVE-2026-88877, fixed in v3.7.12; CVE-2026-46600, fixed in v3.7.13). No pin change is needed because the tag already tracks the patched release, and the prior bump from v3.3 to v3.7 (commit b9690d7) already moved this off the unpatched 3.3 line. - Every other tool install script (bun, claude-code, gemini-cli, openai-codex, opencode, stripe-cli, supabase-cli, uv) installs "latest" with no fixed version to go stale, and the remaining CI actions (docker/*, devcontainers/action, sonarqube-scan-action) are already SHA-pinned to their current major-version releases. - No package.json, requirements.txt, or go.mod exists anywhere in the tree. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RkSKvdVKHBtvwMZX5QQWrR
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



What changed
publish.ymlandpublish-features.ymlstill referencedactions/checkout@v7by the mutable tag, while every other action in these two workflows (and the checkout step insonarqube.yml) is already pinned to a full commit SHA with a version comment. This bumps the two remaining refs to the SHA for the currentv7.0.1release:Verified against the actions/checkout releases page that
v7.0.1is the latestv7.xrelease (no newer patch exists) - so this is a like-for-like immutable pin, not a version bump, matching the repo's own supply-chain-hardening convention.What I checked and did NOT change
Dockerfile base (
mcr.microsoft.com/devcontainers/base:bookworm) - a floating tag on a Debian line supported through June 2028, not a stale fixed version.src/traefik/install.shpins the Traefik Docker image to the floatingtraefik:v3.7tag. That tag currently resolves tov3.7.13(released 2026-09-04), which fixes the two Traefik CVEs disclosed against the 3.7 line this month:CVE-2026-88877(critical auth bypass) - fixed inv3.7.12CVE-2026-46600(HTTP request smuggling) - fixed inv3.7.13No pin change is needed: the tag already tracks the patched release, and the earlier bump from
v3.3tov3.7(commitb9690d7) already moved this off the unpatched 3.3 line.Every other tool install script (
bun,claude-code,gemini-cli,openai-codex,opencode,stripe-cli,supabase-cli,uv) installs "latest" with no fixed version that can go stale.The remaining CI actions (
docker/login-action,docker/metadata-action,docker/setup-buildx-action,docker/build-push-action,devcontainers/action,sonarsource/sonarqube-scan-action) are already SHA-pinned and confirmed current against their major-version release pages.No
package.json,requirements.txt, orgo.modexists anywhere in the tree - this repo is entirely devcontainer feature scripts, a Dockerfile, and CI workflow config.Test plan
publish.yml/publish-features.ymlwith the new pin🤖 Generated with Claude Code
https://claude.ai/code/session_01RkSKvdVKHBtvwMZX5QQWrR
Generated by Claude Code