Skip to content

DEVOPS-1133: Pin GitHub Actions to commit hashes - #133

Open
RomFloreani wants to merge 5 commits into
developfrom
DEVOPS-1133
Open

DEVOPS-1133: Pin GitHub Actions to commit hashes#133
RomFloreani wants to merge 5 commits into
developfrom
DEVOPS-1133

Conversation

@RomFloreani

@RomFloreani RomFloreani commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

DEVOPS-1133 - pin all GitHub actions and reusable workflows to hash
Expands moving GitHub Actions tags to the full semver tag pointing at the same commit, then pins every uses: to a commit hash with a dependabot-readable version comment.

Tags expanded in this repo:

  • MiraGeoscience/CI-tools/.github/workflows/reusable-jira-issue_to_jira.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-jira-pr_actions.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-static_analysis.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-pytest.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_rattler_package.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_pypi_package.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_conda_assets.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_pypi_assets.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-advanced-security.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-annotate.yml@v3 -> @v3.9.1

Copilot AI review requested due to automatic review settings July 29, 2026 16:37
@github-actions github-actions Bot changed the title Pin GitHub Actions to commit hashes DEVOPS-1133: Pin GitHub Actions to commit hashes Jul 29, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates this repository’s GitHub Actions workflow callers to reference the MiraGeoscience/CI-tools reusable workflows at v3.9.1, as part of an effort to move away from the floating v3 major tag.

Changes:

  • Updated multiple reusable-workflow uses: references from @v3 to @v3.9.1 across security, analysis, deploy, and JIRA automation workflows.
  • Standardized all referenced CI-tools reusable workflows to the same minor/patch tag (v3.9.1).

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 6 comments.

Show a summary per file
File Description
.github/workflows/security_scan.yml Bumps referenced Zizmor reusable workflows from v3 to v3.9.1.
.github/workflows/python_deploy_prod.yml Bumps production publish reusable workflows from v3 to v3.9.1.
.github/workflows/python_deploy_dev.yml Bumps development publish reusable workflows from v3 to v3.9.1.
.github/workflows/python_analysis.yml Bumps static analysis + pytest reusable workflows from v3 to v3.9.1.
.github/workflows/pr_jira_actions.yml Bumps PR→JIRA reusable workflow from v3 to v3.9.1.
.github/workflows/issue_to_jira.yml Bumps issue→JIRA reusable workflow from v3 to v3.9.1.
Comments suppressed due to low confidence (4)

.github/workflows/security_scan.yml:43

  • This uses: is still pinned to the v3.9.1 tag, but the PR description says workflows should be pinned to an immutable commit SHA with a dependabot-readable version comment. Pin to the commit behind v3.9.1 instead.
    uses: MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-annotate.yml@v3.9.1

.github/workflows/python_deploy_prod.yml:45

  • This uses: is still pinned to the v3.9.1 tag, but the PR description says workflows should be pinned to an immutable commit SHA with a dependabot-readable version comment. Pin to the commit behind v3.9.1 instead.
    uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_pypi_assets.yml@v3.9.1

.github/workflows/python_deploy_dev.yml:33

  • This uses: is still pinned to the v3.9.1 tag, but the PR description says workflows should be pinned to an immutable commit SHA with a dependabot-readable version comment. Pin to the commit behind v3.9.1 instead.
    uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_pypi_package.yml@v3.9.1

.github/workflows/python_analysis.yml:39

  • This uses: is still pinned to the v3.9.1 tag, but the PR description says workflows should be pinned to an immutable commit SHA with a dependabot-readable version comment. Pin to the commit behind v3.9.1 instead.
    uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-pytest.yml@v3.9.1

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/security_scan.yml Outdated
Comment thread .github/workflows/python_deploy_prod.yml Outdated
Comment thread .github/workflows/python_deploy_dev.yml Outdated
Comment thread .github/workflows/python_analysis.yml Outdated
Comment thread .github/workflows/pr_jira_actions.yml Outdated
Comment thread .github/workflows/issue_to_jira.yml Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants