Skip to content

ci: pin remaining actions/checkout refs to an immutable SHA - #11

Merged
z4nr34l merged 1 commit into
mainfrom
claude/cool-meitner-tw5gur
Sep 21, 2026
Merged

z4nr34l merged 1 commit into
mainfrom
claude/cool-meitner-tw5gur

Conversation

@z4nr34l

@z4nr34l z4nr34l commented Sep 14, 2026

Copy link
Copy Markdown
Member

What changed

publish.yml and publish-features.yml still referenced actions/checkout@v7 by the mutable tag, while every other action in these two workflows (and the checkout step in sonarqube.yml) is already pinned to a full commit SHA with a version comment. This bumps the two remaining refs to the SHA for the current v7.0.1 release:

actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

Verified against the actions/checkout releases page that v7.0.1 is the latest v7.x release (no newer patch exists) - so this is a like-for-like immutable pin, not a version bump, matching the repo's own supply-chain-hardening convention.

What I checked and did NOT change

  • Dockerfile base (mcr.microsoft.com/devcontainers/base:bookworm) - a floating tag on a Debian line supported through June 2028, not a stale fixed version.

  • src/traefik/install.sh pins the Traefik Docker image to the floating traefik:v3.7 tag. That tag currently resolves to v3.7.13 (released 2026-09-04), which fixes the two Traefik CVEs disclosed against the 3.7 line this month:

    • CVE-2026-88877 (critical auth bypass) - fixed in v3.7.12
    • CVE-2026-46600 (HTTP request smuggling) - fixed in v3.7.13

    No pin change is needed: the tag already tracks the patched release, and the earlier bump from v3.3 to v3.7 (commit b9690d7) already moved this off the unpatched 3.3 line.

  • Every other tool install script (bun, claude-code, gemini-cli, openai-codex, opencode, stripe-cli, supabase-cli, uv) installs "latest" with no fixed version that can go stale.

  • The remaining CI actions (docker/login-action, docker/metadata-action, docker/setup-buildx-action, docker/build-push-action, devcontainers/action, sonarsource/sonarqube-scan-action) are already SHA-pinned and confirmed current against their major-version release pages.

  • No package.json, requirements.txt, or go.mod exists anywhere in the tree - this repo is entirely devcontainer feature scripts, a Dockerfile, and CI workflow config.

Test plan

  • CI runs on this PR (workflow syntax unaffected - only the checkout ref changed)
  • Next tag push exercises publish.yml / publish-features.yml with the new pin

🤖 Generated with Claude Code

https://claude.ai/code/session_01RkSKvdVKHBtvwMZX5QQWrR


Generated by Claude Code

publish.yml and publish-features.yml still referenced actions/checkout
by the mutable "v7" tag, while every other action in these workflows
(and the checkout step in sonarqube.yml) is already pinned to a full
commit SHA with a version comment. Bring these two in line with that
convention: actions/checkout@3d3c42e
is the commit for the current v7.0.1 release (verified against the
actions/checkout releases page - no newer v7.x release exists), so
this is a like-for-like pin, not a version bump.

No other outdated or vulnerable pin was found in this pass:
- Dockerfile base (mcr.microsoft.com/devcontainers/base:bookworm) is
  a floating tag on a Debian line supported through 2028, not a stale
  fixed version.
- The traefik feature's install.sh pins the Docker image to the
  floating "traefik:v3.7" tag, which already resolves to v3.7.13
  (released 2026-09-04) - the release that fixes the two Traefik CVEs
  disclosed against the 3.7 line this month (CVE-2026-88877, fixed in
  v3.7.12; CVE-2026-46600, fixed in v3.7.13). No pin change is needed
  because the tag already tracks the patched release, and the prior
  bump from v3.3 to v3.7 (commit b9690d7) already moved this off the
  unpatched 3.3 line.
- Every other tool install script (bun, claude-code, gemini-cli,
  openai-codex, opencode, stripe-cli, supabase-cli, uv) installs
  "latest" with no fixed version to go stale, and the remaining CI
  actions (docker/*, devcontainers/action, sonarqube-scan-action) are
  already SHA-pinned to their current major-version releases.
- No package.json, requirements.txt, or go.mod exists anywhere in the
  tree.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RkSKvdVKHBtvwMZX5QQWrR
@sonarqubecloud

Copy link
Copy Markdown

@z4nr34l
z4nr34l marked this pull request as ready for review September 21, 2026 06:02
@z4nr34l
z4nr34l merged commit 4d26213 into main Sep 21, 2026
5 checks passed
@z4nr34l
z4nr34l deleted the claude/cool-meitner-tw5gur branch September 21, 2026 06:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants