Skip to content

Bump github-tag-action to v7 and pin bump-version.yml actions to commit SHAs - #29

Merged
basi merged 1 commit into
mainfrom
work/dependabot-28-pin-bump-version-actions
Sep 29, 2026
Merged

basi merged 1 commit into
mainfrom
work/dependabot-28-pin-bump-version-actions

Conversation

@basi

@basi basi commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Summary

Supersedes #28.

Dependabot's #28 bumps mathieudutour/github-tag-action from v6.2 to the floating v7 tag. This PR makes the same upgrade and also pins every action in the Bump version workflow (.github/workflows/bump-version.yml) to a full-length commit SHA, with the resolved release tag as a trailing comment. The workflow runs with the repository token and pushes tags and creates releases, so a moved or hijacked tag should not be able to change the code it runs. Dependabot keeps updating SHA-pinned actions (it rewrites both the SHA and the version comment), so this adds no manual upkeep.

Changes

.github/workflows/bump-version.yml only (3 lines):

Action Before After
actions/checkout @v7 @3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
mathieudutour/github-tag-action @v6.2 @af99e60ce8132224b8e6ebab5023449fe256ed46 # v7.0.0
ncipollo/release-action @v1 @339a81892b84b4eeb0f6e744e4574d79d0d9b8dd # v1.21.0

Each SHA is the commit its tag points to (git ls-remote, annotated tags dereferenced with ^{}). Each is also the same commit as the floating tag it replaces (v7, v7, v1). Apart from the github-tag-action upgrade, the code that runs is unchanged. The ncipollo/release-action SHA also matches the one downloaded by the last successful Bump version run.

github-tag-action v7 compatibility

Checked by reading the upstream source at af99e60 and the migration guide. Not verified by running it.

  • Inputs and outputs are unchanged. The inputs this workflow uses (github_token, default_bump, custom_tag) and its outputs (new_tag, changelog) work as before.
    • custom_tag still gets the tag_prefix (v), so new_tag stays v1.2.0.
    • default_bump is not consulted when custom_tag is set.
  • Branch matching: release_branches now matches whole branch names (^master$,^main$). This workflow only runs on pushes to main.
  • Checkout: tags are fetched through the REST API, and fetch_all_tags now defaults to true. The default shallow checkout is still enough, and neither fetch-depth: 0 nor extra permissions are needed.
  • Runtime: v7 runs on Node 24. This removes the Node.js 20 is deprecated … mathieudutour/github-tag-action@v6.2 warning that appears on every run.
  • Upstream reports: no regression issues or open PRs upstream since the v7 release (as of 2026-09-29).

Merge timing

v7 was published on 2026-09-23 09:57 UTC. Following a 7-day cooldown for major updates, please merge on or after 2026-09-30 09:58 UTC.

Verification

  • Re-checked all three tag → SHA mappings with git ls-remote right before committing.
  • Parsed the workflow YAML: the uses: values are the bare SHAs, and the # vX.Y.Z suffixes are comments.
  • Ran actionlint v1.7.12 on .github/workflows/bump-version.yml: no findings (exit 0).
  • The Bump version workflow only runs on push to main, so it cannot run on this PR. The Tests checks here do not exercise it.

Post-merge QA

On the Bump version run for the merge commit:

Out of scope

  • Fixing the pre-existing 422 already_exists failure (for example skipIfReleaseExists: true, or changing how custom_tag is maintained)
  • Pinning the actions in tests.yml (actions/checkout, shivammathur/setup-php, actions/cache)
  • A Dependabot cooldown setting, and an explicit permissions: contents: write

🤖 Generated with Claude Code

Supersede Dependabot PR #28 (mathieudutour/github-tag-action 6.2 -> 7)
and pin every action in the Bump version workflow to a full-length
commit SHA, keeping the resolved release tag as a trailing comment so
Dependabot can keep updating it:

- actions/checkout v7 -> 3d3c42e5aac5ba805825da76410c181273ba90b1 (v7.0.1)
- mathieudutour/github-tag-action v6.2 -> af99e60ce8132224b8e6ebab5023449fe256ed46 (v7.0.0)
- ncipollo/release-action v1 -> 339a81892b84b4eeb0f6e744e4574d79d0d9b8dd (v1.21.0)

A moved or hijacked tag can no longer change the code that runs with
the repository token. github-tag-action v7 targets Node 24, which
removes the Node 20 deprecation warning from every run, and keeps the
inputs and outputs this workflow uses (github_token, default_bump,
custom_tag, new_tag, changelog).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@basi
basi marked this pull request as ready for review September 29, 2026 06:55
@basi
basi merged commit fad1782 into main Sep 29, 2026
4 checks passed
@basi
basi deleted the work/dependabot-28-pin-bump-version-actions branch September 29, 2026 06:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant