You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Sep 22, 2026. It is now read-only.
Repository navigation
This repository was archived by the owner on Sep 22, 2026. It is now read-only.
chore: pin GitHub Actions uses: references to commit SHA instead of tag #728
Part of an org-wide audit of .github/workflows/*.yml and .github/actions/*/action.yml files for GitHub Actions referenced by a mutable tag instead of a full commit SHA. A tag (even a released version tag) can be repointed by the upstream maintainer, or an attacker who compromises their account, without warning; a commit SHA is immutable. This is GitHub's own recommended hardening practice for Actions.
Findings
Switch each uses: line below from tag pinning to SHA pinning, keeping the released version as a trailing comment so the version stays human-readable:
.github/workflows/geoipupdate.yml: pin the four uses: references (lines 20, 26, 28, 73) to full commit SHAs with the version kept as a trailing comment
Approach
Update .github/workflows/geoipupdate.yml to replace each mutable tag reference with the immutable commit SHA listed in the issue: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1, credfeto/action-dotnet-version-detect@d572bbd7285038bda731c8a4f237b9b8e64a9954 # v1.3.0, actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6, and stefanzweifel/git-auto-commit-action@4a55954c782fc1ea30b9056cd3e7a2b40ca8887d # v7. Before committing, each SHA will be independently verified against the upstream repository (for example git ls-remote on the tag) rather than trusted from the issue text, to guard against a poisoned pin. No other workflow in this repo is in scope for this issue.
Test strategy
Validate the edited workflow with actionlint (or the repo's existing YAML lint via .yamllint.yml) to confirm the file still parses, and verify each SHA resolves to the stated tag upstream. The geoipupdate.yml workflow runs on a schedule/dispatch, so after merge trigger a manual workflow_dispatch run to confirm the pinned actions resolve and the job completes.
Assumptions
The four SHAs in the issue correspond to the stated tags; this will be re-verified against upstream before use.
Plan approved - starting implementation: creating a branch, placeholder CHANGELOG entry, and a draft PR now; the actual SHA pinning will land in that PR.
Draft PR opened: #731 - scaffolding only (placeholder CHANGELOG entry) for now; the actual SHA pinning of geoipupdate.yml will be implemented in the PR on the next cycle.
Background
Part of an org-wide audit of
.github/workflows/*.ymland.github/actions/*/action.ymlfiles for GitHub Actions referenced by a mutable tag instead of a full commit SHA. A tag (even a released version tag) can be repointed by the upstream maintainer, or an attacker who compromises their account, without warning; a commit SHA is immutable. This is GitHub's own recommended hardening practice for Actions.Findings
Switch each
uses:line below from tag pinning to SHA pinning, keeping the released version as a trailing comment so the version stays human-readable:.github/workflows/geoipupdate.yml:uses: actions/checkout@v7.0.1->uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1.github/workflows/geoipupdate.yml:uses: actions/setup-dotnet@v6->uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.github/workflows/geoipupdate.yml:uses: credfeto/action-dotnet-version-detect@v1.3.0->uses: credfeto/action-dotnet-version-detect@d572bbd7285038bda731c8a4f237b9b8e64a9954 # v1.3.0.github/workflows/geoipupdate.yml:uses: stefanzweifel/git-auto-commit-action@v7->uses: stefanzweifel/git-auto-commit-action@4a55954c782fc1ea30b9056cd3e7a2b40ca8887d # v7