Repository navigation
ci: pin actions to commit SHAs and add Dependabot - #18
Merged
Merged
Conversation
SECURITY.md says each release ships a CycloneDX SBOM. It did — as a workflow artifact, which expires after 90 days, and nuget.org has no slot for one. The releases for v5.0.0 through v5.0.3 carry no assets, so the statement was true for one quarter per release and then quietly false. A third job, `release`, now runs after `publish`: it creates the GitHub release if none exists (notes taken from the README's "What changed in <version>" section, which ChangelogConsistencyTests already requires for the shipped version — an empty extraction fails the job rather than publishing a blank release) and attaches the per-package `.cdx.json` files. A release created by hand before the tag is pushed is left as written; only the assets are added. It runs after the push so what is attached describes what is on nuget.org, and a failure here costs nothing but a manual upload. Only the SBOMs are attached, deliberately. nuget.org repository-signs every package on ingestion, so a .nupkg downloaded from there never matches ours byte-for-byte; attaching ours would invite a hash comparison that fails for a benign reason, and nuget.org is already the immutable store for the packages. The SBOM has no other home. The job holds contents: write and no id-token; publish holds id-token: write and contents: read. No job holds both. Verified: actionlint clean; the two run blocks executed locally, extracted verbatim from the YAML, with `gh release create/upload` stubbed and `gh release view` live — existing release (v5.0.3) leaves notes alone and exits 0, missing release creates with the extracted section, a view failure that is not "release not found" (401) fails loudly instead of attempting a create, a version with no README section fails, a prerelease version gets --prerelease, and a missing SBOM glob fails. The extraction was checked against every shipped version's section. Not exercised: an actual tag push — the first real run is the next release. Co-Authored-By: Claude Fable 5 <[email protected]>
Every action in both workflows was referenced by major tag. A tag can be moved to a different commit — that is how the tj-actions/changed-files compromise (March 2025) reached every workflow that trusted `@v45` — and NuGet/login runs in the one job that can mint a publishing token. Each reference is now the commit SHA of the current release, with the exact tag in a trailing comment (checkout v6.1.0, setup-dotnet v5.4.0, upload-artifact v6.0.0, download-artifact v7.0.0, NuGet/login v1.2.0), which is what Dependabot reads to propose an update. .github/dependabot.yml keeps the pins current: github-actions weekly, one grouped PR. It also covers the test project's NuGet references monthly, and deliberately not src/ — the EF Core and provider references there are floors chosen on purpose, and raising one raises every consumer's minimum, which is a release decision. The test project's EF Core and provider references track those floors and are ignored for the same reason. Security advisories still surface for everything through Dependabot security updates and NuGetAudit. Verified: SHAs resolved from each repository's peeled tag refs; actionlint clean on both workflows; dependabot.yml parses; ClaudeMdConsistencyTests and PackagingConventionTests pass. Co-Authored-By: Claude Fable 5 <[email protected]>
Owner
Author
|
CI does not run on PRs whose base isn't |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #17 (both touch
release.yml); it retargets tomainonce that merges.Why
Every action in both workflows was referenced by major tag. A tag can be moved to a different commit — that is how the tj-actions/changed-files compromise (March 2025) reached every workflow that trusted
@v45.NuGet/login@v1runs in the one job holdingid-token: write; that is the pin that matters most.What
Every
uses:indotnet.ymlandrelease.ymlis now the commit SHA of the current release, with the exact tag in a trailing comment (Dependabot reads that comment to propose updates):actions/checkoutd23441a…v6.1.0actions/setup-dotnet26b0ec1…v5.4.0actions/upload-artifactb7c566a…v6.0.0actions/download-artifact37930b1…v7.0.0NuGet/login8d19675…v1.2.0.github/dependabot.yml:github-actionsweekly, grouped into one PR, so the pins don't just age;nugetmonthly, test project only, grouped, with the EF Core / provider family ignored.src/is deliberately excluded — its EF Core and provider references are floors chosen on purpose (see the csproj comments), and raising one is a release decision, not a dependency update. Security advisories still surface for everything via Dependabot security updates (already enabled) and NuGetAudit at build.One-paragraph note in each workflow header and in CLAUDE.md so the policy survives the next edit.
Verified
refs/tags/vNand cross-checked against the exact patch tag at that commit.actionlintclean;dependabot.ymlparses.ClaudeMdConsistencyTests,PackagingConventionTestspass.Loosen the nuget scope if you'd rather have Dependabot on
src/too — the ignore list and directory are the only knobs.🤖 Generated with Claude Code