From 53d6d05cc3c2e1aefc9b7543b32f5754142504ad Mon Sep 17 00:00:00 2001 From: Atharv Mantri Date: Mon, 14 Sep 2026 14:48:12 +0530 Subject: [PATCH] fix: enforce locked action dependencies --- action.yml | 4 +++- docs/github-actions.md | 6 ++++-- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/action.yml b/action.yml index 24735f6..0d9d9a9 100644 --- a/action.yml +++ b/action.yml @@ -37,4 +37,6 @@ runs: args+=(--strict) fi - uv run --project "$GITHUB_ACTION_PATH" memoryguard "${args[@]}" + # Fail if the action's committed dependency lock is stale instead of + # resolving a different graph during a user's CI run. + uv run --locked --project "$GITHUB_ACTION_PATH" memoryguard "${args[@]}" diff --git a/docs/github-actions.md b/docs/github-actions.md index 7757609..669d944 100644 --- a/docs/github-actions.md +++ b/docs/github-actions.md @@ -42,8 +42,10 @@ enable strict mode: ``` For production workflows, pin `uses` to a reviewed commit instead of `main`. -The action uses `uv` to run the source in the action checkout; it does not -publish or install a package from PyPI. +The action uses `uv` and the repository's committed lockfile to run the source +in the action checkout; it does not publish or install a package from PyPI. If +the lockfile is stale, the action fails rather than silently resolving a new +dependency graph in CI. ## What the action does