[Core feature request] Pinning action versions to commit hashes updateable by bots
@krzema12 已經在處理了。
開始於 2025年4月27日。
評估
這個 Issue 還沒有評估資料。
描述
What feature do you need?
By default, when using a binding provided by the bindings server, we refer by the major or full version. It can be a branch or a tag. While major version tags/branches change and it's expected, full versions shouldn't. However, technically nothing stops the action owner to hard-reset some full version branch/tag to point to a different commit, and no one will notice it.
That's why, as a part of security hardening, some workflow owners use full SHA-1 of commits they want to use for each action. It guarantees the action's code won't silently change.
Users of github-workflows-kt can already do it using _customVersion constructor argument:
UploadArtifact(
// ...
_customVersion = "actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11",
)
However, dependency updating bots cannot update such commit hashes.
In theory we could try allowing such format when specifying a dependency on an action:
@file:DependsOn("actions:checkout:b4ffde65f46336ab88eb53be808477a3936bae11")
but then, even if we make this commit hash be updated to the right value, there's no mechanism to keep the full version in the comment, like shown in the below example.
Do you have an example usage?
uses: 'actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11' # v4.1.1
Is there a workaround for not having this feature? If yes, please describe it.
No way to make the dependency updating bots work, just specifying the commit hash as version.
- 主要語言
- Kotlin
- 星號
- 665
- 分支
- 30
- 平均合併
- 4 天 19 小時
- 30 天內合併 PR
- 5
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 沒有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
typesafegithub/github-workflows-kt 的其他 Issue
-
bug
難度 3/5 1-2 天 新手友好度 58/100
typesafegithub/github-workflows-kt#2389 · 7 則留言 ·
-
bug
難度 3/5 1-2 天 新手友好度 42/100
typesafegithub/github-workflows-kt#2368 · 1 則留言 ·
-
problem
難度 4/5 3-5 天 新手友好度 42/100
typesafegithub/github-workflows-kt#2348 · 2 則留言 ·
-
Use a lib to interact with GitHub可能已有人在做 @LeoColman 於 554 天前認領。 未關閉operational
typesafegithub/github-workflows-kt#1884 · 已指派 1 人 ·
-
problem
難度 3/5 1-2 天 新手友好度 30/100
typesafegithub/github-workflows-kt#1864 · 5 則留言 ·
查看 typesafegithub/github-workflows-kt 的全部 Issue
相似的 Issue
-
bug
難度 2/5 1-3 小時 新手友好度 68/100
droidconKE/droidconKeKotlin#426 ·
維護者通常 1 天內回覆
-
Crash on Android 14+ when installing extensions: missing FOREGROUND_SERVICE_SHORT_SERVICE permission未關閉
難度 1/5 1 小時以內 新手友好度 78/100
維護者通常 1 天內回覆
-
Bug
難度 2/5 1-3 小時 新手友好度 62/100
keiyoushi/extensions-source#19757 · 1 個 reaction ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 64/100
maplibre/maplibre-native-ffi#792 ·
維護者通常 1 天內回覆
-
難度 1/5 1 小時以內 新手友好度 74/100
維護者通常 1 天內回覆