Repository navigation
ci: pin actions to commit SHAs and add Dependabot - #5
Merged
CaffeinatedCoder merged 1 commit intoAug 16, 2026
Merged
Conversation
Every action in both workflows was referenced by major tag. A tag can be moved to a different commit — that is how the tj-actions/changed-files compromise (March 2025) reached every workflow that trusted `@v45` — and NuGet/login runs in the one job that can mint a publishing token. Each reference is now the commit SHA of the current release, with the exact tag in a trailing comment (checkout v6.1.0, setup-dotnet v5.4.0, upload-artifact v6.0.0, download-artifact v7.0.0, NuGet/login v1.2.0), which is what Dependabot reads to propose an update. .github/dependabot.yml keeps the pins current: github-actions weekly, one grouped PR. It also covers the test projects' NuGet references monthly, and deliberately not src/ — the provider and NodaTime references there are the floors consumers restore against, and raising one is a release decision. The test projects' EF Core and Npgsql references track those floors and are ignored for the same reason. Security advisories still surface for everything through Dependabot security updates and NuGetAudit. Verified: SHAs resolved from each repository's peeled tag refs; actionlint clean on both workflows; dependabot.yml parses; the conventions suite passes. Co-Authored-By: Claude Fable 5 <[email protected]>
Owner
Author
|
CI does not run on PRs whose base isn't |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #4 (both touch
release.yml); it retargets tomainonce that merges. Mirror of EFCore.ComplexIndexes#18.Why
Every action in both workflows was referenced by major tag. A tag can be moved to a different commit — that is how the tj-actions/changed-files compromise (March 2025) reached every workflow that trusted
@v45.NuGet/login@v1runs in the one job holdingid-token: write; that is the pin that matters most.What
uses:indotnet.ymlandrelease.ymlis now the commit SHA of the current release, with the exact tag in a trailing comment (Dependabot reads that comment to propose updates): checkout v6.1.0, setup-dotnet v5.4.0, upload-artifact v6.0.0, download-artifact v7.0.0, NuGet/login v1.2.0..github/dependabot.yml:github-actionsweekly, grouped;nugetmonthly,test/*only, grouped, withMicrosoft.EntityFrameworkCore*andNpgsql*ignored.src/is deliberately excluded — the provider and NodaTime references there are the floors consumers restore against, and raising one is a release decision. Security advisories still surface for everything via Dependabot security updates (already enabled) and NuGetAudit at build.Verified
refs/tags/vNand cross-checked against the exact patch tag at that commit.actionlintclean;dependabot.ymlparses; the conventions suite (31) passes.Loosen the nuget scope if you'd rather have Dependabot on
src/too — the ignore list and directories are the only knobs.🤖 Generated with Claude Code