Skip to content
This repository was archived by the owner on Sep 22, 2026. It is now read-only.
This repository was archived by the owner on Sep 22, 2026. It is now read-only.

chore: pin GitHub Actions uses: references to commit SHA instead of tag #728

Description

@credfeto

Background

Part of an org-wide audit of .github/workflows/*.yml and .github/actions/*/action.yml files for GitHub Actions referenced by a mutable tag instead of a full commit SHA. A tag (even a released version tag) can be repointed by the upstream maintainer, or an attacker who compromises their account, without warning; a commit SHA is immutable. This is GitHub's own recommended hardening practice for Actions.

Findings

Switch each uses: line below from tag pinning to SHA pinning, keeping the released version as a trailing comment so the version stays human-readable:

  • .github/workflows/geoipupdate.yml: uses: actions/checkout@v7.0.1 -> uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
  • .github/workflows/geoipupdate.yml: uses: actions/setup-dotnet@v6 -> uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6
  • .github/workflows/geoipupdate.yml: uses: credfeto/action-dotnet-version-detect@v1.3.0 -> uses: credfeto/action-dotnet-version-detect@d572bbd7285038bda731c8a4f237b9b8e64a9954 # v1.3.0
  • .github/workflows/geoipupdate.yml: uses: stefanzweifel/git-auto-commit-action@v7 -> uses: stefanzweifel/git-auto-commit-action@4a55954c782fc1ea30b9056cd3e7a2b40ca8887d # v7

Activity

  1. added
    AI-WorkWork for an AI Agent
    SecuritySecurity issue, e.g. use of insecure packages, or security fix
    on Jul 21, 2026
  2. credfeto commented on Jul 21, 2026

    @credfeto
    OwnerAuthor

    Implementation Plan

    Files to change

    • .github/workflows/geoipupdate.yml: pin the four uses: references (lines 20, 26, 28, 73) to full commit SHAs with the version kept as a trailing comment

    Approach

    Update .github/workflows/geoipupdate.yml to replace each mutable tag reference with the immutable commit SHA listed in the issue: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1, credfeto/action-dotnet-version-detect@d572bbd7285038bda731c8a4f237b9b8e64a9954 # v1.3.0, actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6, and stefanzweifel/git-auto-commit-action@4a55954c782fc1ea30b9056cd3e7a2b40ca8887d # v7. Before committing, each SHA will be independently verified against the upstream repository (for example git ls-remote on the tag) rather than trusted from the issue text, to guard against a poisoned pin. No other workflow in this repo is in scope for this issue.

    Test strategy

    Validate the edited workflow with actionlint (or the repo's existing YAML lint via .yamllint.yml) to confirm the file still parses, and verify each SHA resolves to the stated tag upstream. The geoipupdate.yml workflow runs on a schedule/dispatch, so after merge trigger a manual workflow_dispatch run to confirm the pinned actions resolve and the job completes.

    Assumptions

    • The four SHAs in the issue correspond to the stated tags; this will be re-verified against upstream before use.

    Open questions

    None, ready to proceed pending approval.

  3. added
    BlockedBlocked by a dependency or external factor
    and removed
    BlockedBlocked by a dependency or external factor
    on Jul 21, 2026
  4. self-assigned this
    on Jul 23, 2026
  5. dnyw4l3n13 commented on Jul 23, 2026

    @dnyw4l3n13
    Collaborator

    Plan approved - starting implementation: creating a branch, placeholder CHANGELOG entry, and a draft PR now; the actual SHA pinning will land in that PR.

  6. dnyw4l3n13 commented on Jul 23, 2026

    @dnyw4l3n13
    Collaborator

    Draft PR opened: #731 - scaffolding only (placeholder CHANGELOG entry) for now; the actual SHA pinning of geoipupdate.yml will be implemented in the PR on the next cycle.

  7. added a commit that references this issue on Jul 23, 2026
  8. added a commit that references this issue on Jul 23, 2026
  9. added a commit that references this issue on Jul 23, 2026
    a0630b5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

AI-WorkWork for an AI AgentSecuritySecurity issue, e.g. use of insecure packages, or security fix

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions