Skip to content

ci: pin actions to commit SHAs and add Dependabot - #5

Merged
CaffeinatedCoder merged 1 commit into
ci/release-assets-sbomfrom
ci/pin-actions-dependabot
Aug 16, 2026
Merged

CaffeinatedCoder merged 1 commit into
ci/release-assets-sbomfrom
ci/pin-actions-dependabot

Conversation

@CaffeinatedCoder

Copy link
Copy Markdown
Owner

Stacked on #4 (both touch release.yml); it retargets to main once that merges. Mirror of EFCore.ComplexIndexes#18.

Why

Every action in both workflows was referenced by major tag. A tag can be moved to a different commit — that is how the tj-actions/changed-files compromise (March 2025) reached every workflow that trusted @v45. NuGet/login@v1 runs in the one job holding id-token: write; that is the pin that matters most.

What

  • Every uses: in dotnet.yml and release.yml is now the commit SHA of the current release, with the exact tag in a trailing comment (Dependabot reads that comment to propose updates): checkout v6.1.0, setup-dotnet v5.4.0, upload-artifact v6.0.0, download-artifact v7.0.0, NuGet/login v1.2.0.
  • .github/dependabot.yml: github-actions weekly, grouped; nuget monthly, test/* only, grouped, with Microsoft.EntityFrameworkCore* and Npgsql* ignored. src/ is deliberately excluded — the provider and NodaTime references there are the floors consumers restore against, and raising one is a release decision. Security advisories still surface for everything via Dependabot security updates (already enabled) and NuGetAudit at build.
  • One-paragraph note in each workflow header so the policy survives the next edit.

Verified

  • SHAs resolved from each repository's peeled refs/tags/vN and cross-checked against the exact patch tag at that commit.
  • actionlint clean; dependabot.yml parses; the conventions suite (31) passes.

Loosen the nuget scope if you'd rather have Dependabot on src/ too — the ignore list and directories are the only knobs.

🤖 Generated with Claude Code

Every action in both workflows was referenced by major tag. A tag can be
moved to a different commit — that is how the tj-actions/changed-files
compromise (March 2025) reached every workflow that trusted `@v45` — and
NuGet/login runs in the one job that can mint a publishing token. Each
reference is now the commit SHA of the current release, with the exact tag
in a trailing comment (checkout v6.1.0, setup-dotnet v5.4.0, upload-artifact
v6.0.0, download-artifact v7.0.0, NuGet/login v1.2.0), which is what
Dependabot reads to propose an update.

.github/dependabot.yml keeps the pins current: github-actions weekly, one
grouped PR. It also covers the test projects' NuGet references monthly, and
deliberately not src/ — the provider and NodaTime references there are the
floors consumers restore against, and raising one is a release decision.
The test projects' EF Core and Npgsql references track those floors and are
ignored for the same reason. Security advisories still surface for
everything through Dependabot security updates and NuGetAudit.

Verified: SHAs resolved from each repository's peeled tag refs; actionlint
clean on both workflows; dependabot.yml parses; the conventions suite passes.

Co-Authored-By: Claude Fable 5 <[email protected]>
@CaffeinatedCoder

Copy link
Copy Markdown
Owner Author

CI does not run on PRs whose base isn't main, so I dispatched the workflow on this branch directly: https://github.com/CaffeinatedCoder/CodoMetis.ValueRanges/actions/runs/31944862180 — green. After #4 merges and this retargets to main, click Update branch (or push) to get the checks on the PR itself.

@CaffeinatedCoder
CaffeinatedCoder merged commit d867a43 into ci/release-assets-sbom Aug 16, 2026
4 checks passed
CaffeinatedCoder added a commit that referenced this pull request Aug 16, 2026
…smoke-test

ci: land the SHA pins, Dependabot and the consumer smoke test on main (recovers #5, #9)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant