fix(ci): SHA-pin scan-and-report steps so sha_pinning callers can start it - #209
hyperpolymath wants to merge 1 commit into
Conversation
…rt it Callers with `sha_pinning_required: true` (e.g. hyperpolymath/echidna) refuse this reusable at startup because its steps used tag refs: The actions actions/checkout@v4.3.1, dtolnay/rust-toolchain@v1, and swatinem/rust-cache@v2.8.2 are not allowed in hyperpolymath/echidna ... A caller's own actions.lock does not cover a cross-repo callee's steps, so the callee must carry commit SHAs itself (same shape as the standards reusables, which start fine under the same policy). #201 had pinned them; #203's `gh actions-lock` rewrite turned them back into tags. - checkout 3d3c42e5 (v7.0.1), rust-toolchain 02cb101e (v1), rust-cache 6323deb1 (v2.9.2); lock entry updated to match by hand (`gh actions-lock` write mode de-pins them again) - `toolchain: v1` -> `stable` (v1 is the action's tag, not a Rust toolchain) - one "managed by gh actions-lock" line after SPDX instead of three Verify (--no-fix) on this file: 0 errors, 3 sha-as-ref warnings; repo total 67 -> 66 findings, none new. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SJGZgoR9ArMgxKcqG7ChW8
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (20)
|
| Layer / File(s) | Summary |
|---|---|
Update workflow header and action pins .github/workflows/scan-and-report.yml |
The workflow header now includes an SPDX identifier and a gh actions-lock management comment. The checkout, Rust toolchain, and Rust cache actions now use pinned commit SHAs with version comments. The Rust toolchain remains set to stable. |
Priority: ➖ Normal
Estimated code review effort: 1 (Trivial) | ~4 minutes
Change: Bug fix
Suggested reviewers: metadatastician
Merge Risk: ⚪ Minimal · up to 153d3
No actionable merge-blocking risk remains from the reviewed changes.
Architecture Summary
Architecture risk: 🔵 Low · up to 153d3
The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.
Changed systems: None identified.
Architecture concerns
No architecture-level concerns identified.
Review details
Before / after behavior
- observed — Modified behavior in .github/workflows/scan-and-report.yml: The workflow header now places the SPDX identifier before the
gh actions-lockmanagement comment, replacing the previous repeated management comments. - observed — Modified behavior in .github/workflows/scan-and-report.yml: The checkout, Rust toolchain, and Rust cache action references now use pinned commit SHAs with version comments instead of version tags; the Rust toolchain input remains
stable.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
| Check name | Status | Explanation |
|---|---|---|
| Title check | ✅ Passed | The title clearly summarises the main change: SHA-pinning the reusable scan-and-report workflow steps so callers with SHA-pinning requirements can start it. |
| Description check | ✅ Passed | The description is directly related to the changeset. It explains the startup failure, the three SHA pins, the toolchain correction, verification results, and the required follow-up. |
| Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0… |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
- Commit to this branch
- Create a new PR
- Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts
Autopilot is currently an internal CodeRabbit preview.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
A rabbit checks each action pin,
Then nibbles clover in the sun.
The toolchain stays on stable ground,
Three SHA pins are safely found.
The workflow header gets its mark,
And bunnies bound off through the park.
Comment @coderabbitai help to get the list of available commands.
Why
hyperpolymath/echidnahassha_pinning_required: true. Its Security Scan calls this reusable and has ended instartup_failuresince the pinning rule landed. The run page for echidna run 36185528155 says:actions/checkoutis GitHub-owned, and echidna hasgithub_owned_allowed: true. So the allow-list is not the cause; the tag refs are.A caller's own
actions.lockdoes not cover a cross-repo callee's steps, so the callee has to carry commit SHAs itself.Positive control: echidna's Scorecard and Secret Scanner succeed through
standards/*-reusable.yml@571cc73, whose steps are written@<sha> # vX.#201 had pinned these steps. #203's
gh actions-lockrewrite turned them back into tags.Change
actions/checkout@3d3c42e5(v7.0.1)dtolnay/rust-toolchain@02cb101e(v1)Swatinem/rust-cache@6323deb1(v2.9.2)actions.lockentry by hand to match, becausegh actions-lockwrite mode de-pins the steps again.toolchain: v1tostable.v1is the action's tag, not a Rust toolchain.Verification
gh actions-lock --no-fix --json:sha-as-refwarnings (the same advisory the standards reusables carry).Follow-up
echidna's
security-scan.ymlhas to bump its callee pin to this merge commit (echidna#310).🤖 Generated with Claude Code
https://claude.ai/code/session_01SJGZgoR9ArMgxKcqG7ChW8