From b245973c1566b0a30dcbb21c19e5dd7516cc86f3 Mon Sep 17 00:00:00 2001 From: Omar Shahine <10343873+omarshahine@users.noreply.github.com> Date: Tue, 1 Sep 2026 05:47:40 +0000 Subject: [PATCH] ci: pin GitHub Actions to commit SHAs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A mutable major tag (`@v7`, `@v4`) is a moving target: upstream can retarget it at any time, and these workflows hold production credentials. Pinning to a full commit SHA makes the code that runs deterministic. Each `uses:` keeps its version in a trailing comment (`# v7`) so the file stays readable, and Dependabot's `github-actions` ecosystem — already configured here — uses that comment to keep both the SHA and the annotation current. Every SHA was resolved from the tag it currently points at via `/repos///git/ref/tags/`, dereferencing annotated tag objects to their commit, and re-resolved per repo rather than copied between them. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01VDD6P9ft7DNNbrXpNWvCsk --- .github/workflows/plugin-inspector.yml | 6 +++--- .github/workflows/publish-clawhub.yml | 4 ++-- .github/workflows/publish-homebrew.yml | 2 +- .github/workflows/publish-npm.yml | 4 ++-- 4 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/plugin-inspector.yml b/.github/workflows/plugin-inspector.yml index 963b793..4892507 100644 --- a/.github/workflows/plugin-inspector.yml +++ b/.github/workflows/plugin-inspector.yml @@ -12,8 +12,8 @@ jobs: run: working-directory: openclaw steps: - - uses: actions/checkout@v7 - - uses: actions/setup-node@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: node-version: 24 cache: npm @@ -24,7 +24,7 @@ jobs: # "//" note there before removing either. - run: npm run typecheck - run: npx @openclaw/plugin-inspector ci --no-openclaw --runtime --mock-sdk --allow-execute - - uses: actions/upload-artifact@v7 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 if: always() with: name: plugin-inspector-reports diff --git a/.github/workflows/publish-clawhub.yml b/.github/workflows/publish-clawhub.yml index d2f29d3..0120f6f 100644 --- a/.github/workflows/publish-clawhub.yml +++ b/.github/workflows/publish-clawhub.yml @@ -14,10 +14,10 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - name: Setup Node.js - uses: actions/setup-node@v7 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: node-version: 22 diff --git a/.github/workflows/publish-homebrew.yml b/.github/workflows/publish-homebrew.yml index b541055..c303859 100644 --- a/.github/workflows/publish-homebrew.yml +++ b/.github/workflows/publish-homebrew.yml @@ -44,7 +44,7 @@ jobs: echo "Resolved v$VERSION -> $SHA256" - name: Checkout tap - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: repository: ${{ env.TAP_REPO }} token: ${{ secrets.HOMEBREW_TAP_TOKEN }} diff --git a/.github/workflows/publish-npm.yml b/.github/workflows/publish-npm.yml index 90cd17f..60b7292 100644 --- a/.github/workflows/publish-npm.yml +++ b/.github/workflows/publish-npm.yml @@ -15,12 +15,12 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - name: Setup Node.js # Node 24 ships with npm 11.x. Trusted Publisher OIDC requires # npm >= 11.5.1 (per https://docs.npmjs.com/trusted-publishers). - uses: actions/setup-node@v7 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: node-version: 24 registry-url: "https://registry.npmjs.org"