diff --git a/action.yml b/action.yml index 24735f6..0d9d9a9 100644 --- a/action.yml +++ b/action.yml @@ -37,4 +37,6 @@ runs: args+=(--strict) fi - uv run --project "$GITHUB_ACTION_PATH" memoryguard "${args[@]}" + # Fail if the action's committed dependency lock is stale instead of + # resolving a different graph during a user's CI run. + uv run --locked --project "$GITHUB_ACTION_PATH" memoryguard "${args[@]}" diff --git a/docs/github-actions.md b/docs/github-actions.md index 7757609..669d944 100644 --- a/docs/github-actions.md +++ b/docs/github-actions.md @@ -42,8 +42,10 @@ enable strict mode: ``` For production workflows, pin `uses` to a reviewed commit instead of `main`. -The action uses `uv` to run the source in the action checkout; it does not -publish or install a package from PyPI. +The action uses `uv` and the repository's committed lockfile to run the source +in the action checkout; it does not publish or install a package from PyPI. If +the lockfile is stale, the action fails rather than silently resolving a new +dependency graph in CI. ## What the action does