Skip to content

fix(github): pin cache action revision - #3

Draft
seonghobae wants to merge 2 commits into
apk-cache-cleanupfrom
cache-action-pin
Draft

seonghobae wants to merge 2 commits into
apk-cache-cleanupfrom
cache-action-pin

Conversation

@seonghobae

@seonghobae seonghobae commented Oct 1, 2026 •

Copy link
Copy Markdown

Issue for this PR

Blocked: repository Issues are disabled. The issue creation API returned HTTP 410, so a canonical issue cannot currently be linked. The originating exact evidence is OpenCode PR #2 SAST run 36848110084, job 110323025333, rule yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag at github/action.yml:53.

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

The published composite action executed mutable actions/cache@v4 in every consumer runner. This PR pins the official v4.3.0 commit 0057852bfaa89a56745cba8c7296529d2fc39830, adds a structural production-file contract, and records the RCA in CHANGELOG, doctoring, and docs/product-technical-gap-baseline.md.

Two independently found oracle misses are retained as executable fixtures:

  1. inert YAML text cannot satisfy the check while an executable step remains mutable;
  2. case-varied Actions/Cache and actions/cache/{restore,save} edges are classified as the same repository.

The test parses runs.steps[*].uses with Bun.YAML.parse, canonicalizes repository case, and covers same-repository sub-actions. No scanner suppression, copied workflow, or consumer workaround is introduced.

How did you verify your code works?

  • Exact stack: base PR fix(opencode): harden runtime image #2 head 9d05f4f11fbd48cd909e5355591a66563010ff12; current head c15dabc57a495ecb5e324b7ae4fe50c255212ab9; GitHub reports mergeable.
  • Official upstream identity: actions/cache@0057852
  • Focused Bun verification from packages/opencode: 6 passed, 0 failed, 7 assertions.
  • Independent full-delta review found no remaining concrete source, security, scope, or oracle defect.
  • Hosted test run 36853164446 exists at the exact head, but all four jobs remain queued and are not claimed GREEN.
  • Stacked-base rules currently omit typecheck, nix-eval, central SAST/security, and automatic model review. That owner/control-plane Gap remains a merge gate.

Screenshots / recordings

Not applicable; this is a GitHub Action supply-chain repair with no UI change.

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

Ownership and stack

This OpenCode-owned source repair is stacked on #2 (apk-cache-cleanup) without copying or dropping its delta. The five-file change is two ordinary commits ahead of the exact base and zero behind.

Merge state

Draft / Proposed / merge HOLD. The bounded source delta is reviewable, but exact base #2 is a mutable Draft prerequisite with substantive exact-head SAST/Trivy failures and queued product jobs. That unready prerequisite is the Draft reason; queued Checks and missing approval alone are not. Fresh exact-head Checks, repair or equivalent exact-revision evidence for the stacked-base workflow coverage Gap, and an independent APPROVED review remain required before ordinary merge. Queued, skipped, missing, and status-only results are not passing evidence.

Summary by CodeRabbit

  • 보안 및 안정성
    • OpenCode GitHub Action의 캐시 참조를 검토된 버전의 변경 불가 커밋으로 고정했습니다. 이에 따라 외부 태그 변경으로 캐시 동작이 예기치 않게 달라지는 위험을 줄이고, 작업 실행의 일관성을 높였습니다.
    • 캐시 참조가 지정된 커밋을 유지하는지 확인하는 회귀 검증을 추가했습니다.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: dce49d89-27f6-45bf-92f3-76264c9bf7ae

📥 Commits

Reviewing files that changed from the base of the PR and between 9d05f4f and c15dabc.

📒 Files selected for processing (5)
  • CHANGELOG.md
  • docs/doctoring/github-action-cache-pin-20261001.md
  • docs/product-technical-gap-baseline.md
  • github/action.yml
  • packages/opencode/test/security/github-action-dependency.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

OpenCode GitHub Action의 actions/cache 참조를 v4.3.0 커밋 SHA로 고정했습니다. 실행 단계의 캐시 참조를 추출하고 고정된 커밋과 비교하는 테스트 및 관련 문서를 추가했습니다.

Changes

캐시 액션 참조 고정

Layer / File(s) Summary
캐시 참조 고정 및 검증
github/action.yml, packages/opencode/test/security/github-action-dependency.test.ts, docs/doctoring/github-action-cache-pin-20261001.md, docs/product-technical-gap-baseline.md, CHANGELOG.md
GitHub Action의 캐시 참조를 v4.3.0 커밋 SHA로 변경했습니다. 테스트는 실행 단계에서 actions/cache 및 하위 액션 참조를 추출하고, 게시된 액션의 참조가 지정된 커밋과 일치하는지 검사합니다. 문서와 변경 내역에 수정 사항과 검증 조건을 기록했습니다.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to c15da

The cache dependency is pinned and regression coverage is reported. No actionable code-level merge risk is established; the reported hosted checks remain pending.

Security Architecture Review

Security architecture risk: 🔵 Low · up to c15da

The change reduces dependency-substitution risk without changing the action’s inputs, cache configuration, or execution sequence. No introduced security concern was established. The selected upstream implementation and consumer-specific permissions were not independently assessed.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The dependency executes in consumer jobs that adopt this composite-action revision. Its potential impact is bounded by each job’s available workspace, credentials, and network access; the PR does not add a new execution step or expand the declared input surface. Actual consumer authority is not supplied.

Trust Boundaries and Controls

  • inferred — Previously, control over the mutable upstream tag could change the cache implementation executed by consumers without an edit here. The fixed SHA closes that tag-movement path for this dependency while retaining the existing upstream-code-to-runner trust boundary.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (4 skipped: 4 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed 제목은 주요 변경 사항인 GitHub Actions cache action의 커밋 고정을 정확하고 간결하게 설명합니다.
Description check ✅ Passed 설명은 이슈 정보, 변경 유형, 변경 내용, 검증 방법, 스크린샷 여부, 체크리스트, 소유권 및 병합 상태를 포함합니다. 현재 호스팅 검사는 대기 중이며 병합 보류 사유도 명확하게 기록되어 있습니다.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (4 skipped: 4 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Thanks for your contribution!

This PR doesn't have a linked issue. All PRs must reference an existing issue.

Please:

  1. Open an issue describing the bug/feature (if one doesn't exist)
  2. Add Fixes #<number> or Closes #<number> to this PR description

See CONTRIBUTING.md for details.

Copy link
Copy Markdown
Author

Exact-head repair evidence for c15dabc57a495ecb5e324b7ae4fe50c255212ab9:

  • Independent review confirmed both oracle findings closed: inert YAML text cannot satisfy the structural check, and repository identity matching now covers case variants plus actions/cache/* sub-actions.
  • No remaining concrete correctness, security, scope, or oracle defect was found in the full delta against 9d05f4f11fbd48cd909e5355591a66563010ff12.
  • Focused local verification: 6 pass, 0 fail, 7 assertions across the dependency and runtime-image security tests.
  • Hosted exact-head workflow run 36853164446 is queued (four jobs queued). This PR remains Draft / Proposed; queued Checks and the absence of an APPROVED review are not treated as completion.

@seonghobae
seonghobae marked this pull request as ready for review October 1, 2026 11:54

Copy link
Copy Markdown
Author

@coderabbitai review

Please review exact head c15dabc57a495ecb5e324b7ae4fe50c255212ab9 against stacked base 9d05f4f11fbd48cd909e5355591a66563010ff12. Focus on mutable-action identity, executable YAML edge discovery, inert-text/vacuous-oracle bypasses, case-insensitive repository identity, and actions/cache/* sub-actions. This is review admission only; do not infer merge authorization from Ready state.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Thanks for updating your PR! It now meets our contributing guidelines. 👍

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Author

Current authority — stacked prerequisite admission correction

Exact head c15dabc57a495ecb5e324b7ae4fe50c255212ab9 is mechanically mergeable and its bounded cache-action pin remains source-complete, but its exact base is mutable Draft prerequisite #2 at 9d05f4f11fbd48cd909e5355591a66563010ff12.

Fresh exact-head evidence before this state correction:

Therefore the unready mutable prerequisite is a valid Draft reason under the current concurrency authority. This exact head is converted Ready → Draft once in this run. No source ref, head SHA, base, check run, rerun, cancellation, or wake generation is changed. Return to Ready only after #2 becomes an immutable integrated prerequisite or an exact-head authority record proves the prerequisite is no longer mutable/unready.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant