Skip to content

Pin GitHub Actions to full-length commit SHAs - #126

Closed
pditommaso wants to merge 1 commit into
masterfrom
pin-actions-sha
Closed

pditommaso wants to merge 1 commit into
masterfrom
pin-actions-sha

Conversation

@pditommaso

Copy link
Copy Markdown
Contributor

Summary

CI is currently failing on every PR at the "Set up job" step with:

The actions actions/checkout@v4, graalvm/setup-graalvm@v1, and actions/upload-artifact@v4 are not allowed in seqeralabs/wave-cli because all actions must be pinned to a full-length commit SHA.

The seqeralabs org now enforces that all GitHub Actions be pinned to a full-length commit SHA. This PR pins every action in .github/workflows/ accordingly so CI runs again.

Changes

Each action is pinned to the commit SHA of its current major version (no functional/major upgrade), with the resolved version recorded in a trailing comment:

Action Version SHA
actions/checkout v4.4.0 11d5960a326750d5838078e36cf38b85af677262
graalvm/setup-graalvm v1.6.6 0426e2e191540e8514dff98dc52a5f5146a2a276
actions/upload-artifact v4.6.2 ea165f8d65b6e75b540449e92b4886f43607fa02
actions/download-artifact v4.3.0 d3f86a106a0bac45b974a628896c90dbdf5c8093
actions/setup-java v4.9.1 cf277c60eb25467037889841efdb72551f06f6c3
gradle/actions (dependency-submission) v4.4.3 ed408507eac070d1f99cc633dbcf757c94c7933a
jreleaser/release-action v2 97b5e2f0e845de2fe1dbbdf451ac6a21233fafff

Files touched: .github/workflows/build.yml, .github/workflows/security-submit-dependecy-graph.yml.

Note: this intentionally pins to the existing major versions rather than bumping to the latest majors, to avoid mixing an infra fix with potentially breaking upgrades. Major version bumps can be done separately.

🤖 Generated with Claude Code

The seqeralabs org policy requires all GitHub Actions to be pinned to a
full-length commit SHA, which was causing every CI job to fail at "Set up
job" with: "the actions ... are not allowed ... because all actions must be
pinned to a full-length commit SHA".

Pin each action to the commit SHA of its current major version (with the
resolved version noted in a trailing comment) so CI runs again:
- actions/checkout            -> v4.4.0
- graalvm/setup-graalvm       -> v1.6.6
- actions/upload-artifact     -> v4.6.2
- actions/download-artifact   -> v4.3.0
- actions/setup-java          -> v4.9.1
- gradle/actions              -> v4.4.3
- jreleaser/release-action    -> v2

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@pditommaso

Copy link
Copy Markdown
Contributor Author

Superseded — master already pins every GitHub Action to a full-length commit SHA via Renovate (#110–#116), which resolves the org-policy CI failure this PR was addressing. No remaining @vN tags on master, so this PR is redundant. Closing.

@pditommaso pditommaso closed this Sep 14, 2026
@pditommaso
pditommaso deleted the pin-actions-sha branch September 14, 2026 19:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant