Skip to content

chore(ci): update check-permissions action to pull latest - #8437

Merged
wise-king-sullyman merged 1 commit into
patternfly:mainfrom
wise-king-sullyman:update-check-permissions-action
Jun 1, 2026
Merged

wise-king-sullyman merged 1 commit into
patternfly:mainfrom
wise-king-sullyman:update-check-permissions-action

Conversation

@wise-king-sullyman

@wise-king-sullyman wise-king-sullyman commented Jun 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary by CodeRabbit

Release Notes

This update addresses internal infrastructure and contains no user-facing changes or features.

  • Chores
    • Updated internal CI/CD workflow configuration.

@coderabbitai

coderabbitai Bot commented Jun 1, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Walkthrough

The PR updates the PR preview workflow to reference the check-team-membership.yml reusable workflow using the @main branch instead of a previously pinned commit SHA, ensuring the team membership check job runs against the latest version of that shared workflow.

Changes

Workflow Reference Update

Layer / File(s) Summary
Reusable workflow reference update
.github/workflows/pr-preview.yml
The check-permissions job uses: pin for check-team-membership.yml is changed from a specific commit SHA to @main, allowing the workflow to use the latest version of the shared team membership check workflow.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

  • patternfly/patternfly#8341: Both PRs modify the check-permissions reusable workflow call reference in .github/workflows/pr-preview.yml for team membership verification.
🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title follows conventional commit format with 'chore(ci):' prefix and clearly summarizes the main change of updating the check-permissions action reference.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/pr-preview.yml:
- Around line 9-10: The reusable workflow reference currently uses a mutable ref
"patternfly/.github/.github/workflows/check-team-membership.yml@main"; update
that "uses:" value to a full commit SHA (e.g., replace "`@main`" with the exact
commit hash) so the workflow is pinned and cannot change unexpectedly while
still keeping "secrets: inherit". Locate the "uses:
patternfly/.github/.github/workflows/check-team-membership.yml@main" entry and
substitute the branch ref with the chosen immutable commit SHA.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1ab2c355-77ee-4245-bdc8-34e01205901e

📥 Commits

Reviewing files that changed from the base of the PR and between 15eec94 and 57d4fc0.

📒 Files selected for processing (1)
  • .github/workflows/pr-preview.yml

Comment on lines +9 to 10
uses: patternfly/.github/.github/workflows/check-team-membership.yml@main
secrets: inherit

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🌐 Web query:

What do GitHub Actions security best practices recommend for reusable workflow uses:references: pinning by branch/tag (e.g.,@main) vs full commit SHA?

💡 Result:

Best practice: prefer pinning reusable workflow uses: references to a full-length commit SHA over pinning to a branch/tag like @main (or @v1). Pinning to a full-length commit SHA is GitHub’s recommended way to make the referenced code effectively immutable, and it’s the only approach GitHub states provides immutable “release” semantics for Actions. [1] What GitHub recommends about branch/tag pins vs commit SHAs 1) Pin to full-length commit SHA for immutability - GitHub docs state: “Pinning an action to a full-length commit SHA is currently the only way to use an action as an immutable release.” [1] - GitHub further explains SHA pinning mitigates risk from a bad actor adding backdoor code to the action’s repository, because they would need to generate a SHA-1 collision for a valid Git object payload. [1] - GitHub also supports enforcing SHA pinning via policy; if a workflow attempts to use an action that isn’t pinned to a full-length SHA, the workflow fails. [2] 2) Pin to a tag only if you trust the creator (and still accept residual risk) - GitHub notes pinning to a tag is more convenient and widely used, but cautions: “Pin actions to a tag only if you trust the action’s creators.” [1] - GitHub adds that tag risk remains even if you trust the author, because a tag “can be moved or deleted” if an attacker gains access to the action’s repository. [1] How this maps specifically to reusable workflows (uses: owner/repo/.github/workflows/...@...) - GitHub’s enterprise policy documentation states: “Require actions to be pinned to a full-length commit SHA… Reusable workflows can still be referenced by tag.” [3] - That implies GitHub recognizes (and policy enforcement may not yet fully constrain) reusable workflows differently than standard Actions. Nevertheless, GitHub also explicitly links reusable-workflow security to the same “good practices” as for third-party workflows. [1] - GitHub’s reusable-workflow configuration docs also state the same conditional guidance: using a commit SHA ensures everyone always uses the same YAML, while tags/branches require trust in that version. [4] Answer to your specific question (pin by branch/tag like @main vs full commit SHA) - If you want the strongest supply-chain and immutability properties: pin the reusable workflow reference to a full-length commit SHA, not @main/tags. [1][4] - If you must use tags/branches: treat that as a weaker control that depends on your trust in the workflow publisher, and understand that tags/branches are mutable and can be moved or deleted (creating a risk window). [1][4] Practical guidance - Prefer: uses: OWNER/REPO/.github/workflows/workflow.yml@<full-commit-sha>. - Avoid: uses: OWNER/REPO/.github/workflows/workflow.yml@main for security-hardening contexts, because it follows a moving reference rather than an immutable one. (GitHub’s immutability guidance is tied to full commit SHAs, while tag/branch references depend on trust and mutability risks.) [1][4]

Citations:


🏁 Script executed:

#!/bin/bash
set -euo pipefail
FILE=".github/workflows/pr-preview.yml"
if [ -f "$FILE" ]; then
  echo "== $FILE =="
  nl -ba "$FILE" | sed -n '1,40p'
else
  echo "File not found: $FILE" >&2
  exit 1
fi

Repository: patternfly/patternfly

Length of output: 166


🏁 Script executed:

#!/bin/bash
set -euo pipefail
FILE=".github/workflows/pr-preview.yml"
if [ -f "$FILE" ]; then
  echo "== $FILE (lines 1-25) =="
  cat -n "$FILE" | sed -n '1,25p'
else
  echo "File not found: $FILE" >&2
  exit 1
fi

Repository: patternfly/patternfly

Length of output: 1092


Pin the reusable workflow uses: reference to a full commit SHA (not @main)

.github/workflows/pr-preview.yml uses patternfly/.github/.github/workflows/check-team-membership.yml@main with secrets: inherit, so any upstream change to main can alter the permission gate while still receiving inherited secrets. Pin uses: to an immutable commit SHA.

🔒 Suggested fix
-    uses: patternfly/.github/.github/workflows/check-team-membership.yml@main
+    uses: patternfly/.github/.github/workflows/check-team-membership.yml@<full_commit_sha>
🧰 Tools
🪛 zizmor (1.25.2)

[warning] 8-10: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block

(excessive-permissions)


[error] 9-9: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[warning] 9-9: secrets unconditionally inherited by called workflow (secrets-inherit): this reusable workflow

(secrets-inherit)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/pr-preview.yml around lines 9 - 10, The reusable workflow
reference currently uses a mutable ref
"patternfly/.github/.github/workflows/check-team-membership.yml@main"; update
that "uses:" value to a full commit SHA (e.g., replace "`@main`" with the exact
commit hash) so the workflow is pinned and cannot change unexpectedly while
still keeping "secrets: inherit". Locate the "uses:
patternfly/.github/.github/workflows/check-team-membership.yml@main" entry and
substitute the branch ref with the chosen immutable commit SHA.

@patternfly-build

patternfly-build commented Jun 1, 2026 •

Copy link
Copy Markdown
Collaborator

@wise-king-sullyman
wise-king-sullyman merged commit 718063b into patternfly:main Jun 1, 2026
6 checks passed
@patternfly-build

Copy link
Copy Markdown
Collaborator

🎉 This PR is included in version 6.6.0-prerelease.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants