Skip to content

ci: pin actions to commit SHAs and add Dependabot - #18

Merged
CaffeinatedCoder merged 2 commits into
mainfrom
ci/pin-actions-dependabot
Aug 16, 2026
Merged

CaffeinatedCoder merged 2 commits into
mainfrom
ci/pin-actions-dependabot

Conversation

@CaffeinatedCoder

Copy link
Copy Markdown
Owner

Stacked on #17 (both touch release.yml); it retargets to main once that merges.

Why

Every action in both workflows was referenced by major tag. A tag can be moved to a different commit — that is how the tj-actions/changed-files compromise (March 2025) reached every workflow that trusted @v45. NuGet/login@v1 runs in the one job holding id-token: write; that is the pin that matters most.

What

  • Every uses: in dotnet.yml and release.yml is now the commit SHA of the current release, with the exact tag in a trailing comment (Dependabot reads that comment to propose updates):

    action pinned
    actions/checkout d23441a… v6.1.0
    actions/setup-dotnet 26b0ec1… v5.4.0
    actions/upload-artifact b7c566a… v6.0.0
    actions/download-artifact 37930b1… v7.0.0
    NuGet/login 8d19675… v1.2.0
  • .github/dependabot.yml: github-actions weekly, grouped into one PR, so the pins don't just age; nuget monthly, test project only, grouped, with the EF Core / provider family ignored. src/ is deliberately excluded — its EF Core and provider references are floors chosen on purpose (see the csproj comments), and raising one is a release decision, not a dependency update. Security advisories still surface for everything via Dependabot security updates (already enabled) and NuGetAudit at build.

  • One-paragraph note in each workflow header and in CLAUDE.md so the policy survives the next edit.

Verified

  • SHAs resolved from each repository's peeled refs/tags/vN and cross-checked against the exact patch tag at that commit.
  • actionlint clean; dependabot.yml parses.
  • ClaudeMdConsistencyTests, PackagingConventionTests pass.

Loosen the nuget scope if you'd rather have Dependabot on src/ too — the ignore list and directory are the only knobs.

🤖 Generated with Claude Code

CaffeinatedCoder and others added 2 commits August 16, 2026 13:15
SECURITY.md says each release ships a CycloneDX SBOM. It did — as a workflow
artifact, which expires after 90 days, and nuget.org has no slot for one. The
releases for v5.0.0 through v5.0.3 carry no assets, so the statement was true
for one quarter per release and then quietly false.

A third job, `release`, now runs after `publish`: it creates the GitHub
release if none exists (notes taken from the README's "What changed in
<version>" section, which ChangelogConsistencyTests already requires for the
shipped version — an empty extraction fails the job rather than publishing a
blank release) and attaches the per-package `.cdx.json` files. A release
created by hand before the tag is pushed is left as written; only the assets
are added. It runs after the push so what is attached describes what is on
nuget.org, and a failure here costs nothing but a manual upload.

Only the SBOMs are attached, deliberately. nuget.org repository-signs every
package on ingestion, so a .nupkg downloaded from there never matches ours
byte-for-byte; attaching ours would invite a hash comparison that fails for
a benign reason, and nuget.org is already the immutable store for the
packages. The SBOM has no other home.

The job holds contents: write and no id-token; publish holds id-token: write
and contents: read. No job holds both.

Verified: actionlint clean; the two run blocks executed locally, extracted
verbatim from the YAML, with `gh release create/upload` stubbed and `gh
release view` live — existing release (v5.0.3) leaves notes alone and exits 0,
missing release creates with the extracted section, a view failure that is
not "release not found" (401) fails loudly instead of attempting a create,
a version with no README section fails, a prerelease version gets
--prerelease, and a missing SBOM glob fails. The extraction was checked
against every shipped version's section. Not exercised: an actual tag push —
the first real run is the next release.

Co-Authored-By: Claude Fable 5 <[email protected]>
Every action in both workflows was referenced by major tag. A tag can be
moved to a different commit — that is how the tj-actions/changed-files
compromise (March 2025) reached every workflow that trusted `@v45` — and
NuGet/login runs in the one job that can mint a publishing token. Each
reference is now the commit SHA of the current release, with the exact tag
in a trailing comment (checkout v6.1.0, setup-dotnet v5.4.0, upload-artifact
v6.0.0, download-artifact v7.0.0, NuGet/login v1.2.0), which is what
Dependabot reads to propose an update.

.github/dependabot.yml keeps the pins current: github-actions weekly, one
grouped PR. It also covers the test project's NuGet references monthly, and
deliberately not src/ — the EF Core and provider references there are floors
chosen on purpose, and raising one raises every consumer's minimum, which is
a release decision. The test project's EF Core and provider references track
those floors and are ignored for the same reason. Security advisories still
surface for everything through Dependabot security updates and NuGetAudit.

Verified: SHAs resolved from each repository's peeled tag refs; actionlint
clean on both workflows; dependabot.yml parses; ClaudeMdConsistencyTests
and PackagingConventionTests pass.

Co-Authored-By: Claude Fable 5 <[email protected]>
@CaffeinatedCoder

Copy link
Copy Markdown
Owner Author

CI does not run on PRs whose base isn't main, so I dispatched the workflow on this branch directly: https://github.com/CaffeinatedCoder/EFCore.ComplexIndexes/actions/runs/31944860488 — all four jobs green. After #17 merges and this retargets to main, click Update branch (or push) to get the checks on the PR itself.

@CaffeinatedCoder
CaffeinatedCoder changed the base branch from ci/release-assets-sbom to main August 16, 2026 12:31
@CaffeinatedCoder
CaffeinatedCoder merged commit 60499e1 into main Aug 16, 2026
9 checks passed
@CaffeinatedCoder
CaffeinatedCoder deleted the ci/pin-actions-dependabot branch August 16, 2026 13:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant