Skip to content

fix: repair SHA-pinned Action resolution and Code Scanning - #32

Merged
BLCCoreStudio merged 5 commits into
mainfrom
fix/sha-pin-code-scanning
Aug 30, 2026
Merged

BLCCoreStudio merged 5 commits into
mainfrom
fix/sha-pin-code-scanning

Conversation

@BLCCoreStudio

Copy link
Copy Markdown
Owner

Summary

  • remove the stale hard-coded v0.1.0 fallback for non-tag Action refs
  • resolve immutable SHA/branch refs to the release version declared by the pinned Action source's Cargo.toml
  • dogfood the current checkout in the repository's Code Scanning workflow instead of invoking an old published Action commit
  • bump the package/test expectation to 0.2.3

Why

The Code Scanning workflow was pinned to an older Action commit. Because non-tag refs fell back to v0.1.0, the workflow downloaded a binary that did not support --sarif, causing Code Scanning to fail. The same fallback also made the README's immutable-SHA pinning guidance unreliable for newer Action features.

Security

  • release binary downloads remain SHA-256 verified
  • the repository's Code Scanning workflow now builds and scans the exact checked-out source
  • no new repository write permissions are introduced

Release

After CI is green and this merges, publish v0.2.3 through the existing Marketplace release flow.

@github-actions github-actions Bot added dependencies Dependency updates github-actions GitHub Actions and CI automation labels Aug 30, 2026
@BLCCoreStudio
BLCCoreStudio enabled auto-merge (squash) August 30, 2026 19:48
@BLCCoreStudio
BLCCoreStudio merged commit b05fda8 into main Aug 30, 2026
8 checks passed
@BLCCoreStudio
BLCCoreStudio deleted the fix/sha-pin-code-scanning branch August 30, 2026 19:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates github-actions GitHub Actions and CI automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant