Pin GitHub Actions to commit SHAs - #160
Merged
Merged
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
The release workflow retains an unpinned mutable action reference.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Pins GitHub Actions dependencies to immutable SHAs and configures automated weekly updates.
Changes:
- Pins six action references to commit SHAs.
- Adds a seven-day Dependabot cooldown.
- One multiline
actions/setup-go@v4reference remains unpinned.
File summaries
| File | Description |
|---|---|
.github/workflows/test.yml |
Pins test actions. |
.github/workflows/release.yml |
Pins two release actions. |
.github/workflows/lint.yml |
Pins lint actions. |
.github/dependabot.yml |
Enables weekly action updates. |
Review details
- Files reviewed: 4/4 changed files
- Comments generated: 1
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Pin the omitted actions/setup-go v4 reference to its resolved commit without changing the Go toolchain or release behavior. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use the supported macos-15 image for the macOS leg while retaining its existing check name. macOS 26 dyld rejects Go 1.21.3 internal-linker binaries without LC_UUID; preserve the established Go toolchain instead of bumping it. Keep Linux/Windows runners, all SHA pins, build steps, race tests, timeouts, and matrix coverage unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
mrecachinas
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pins external GitHub Actions to immutable commit SHAs and restores compatibility of the existing Go test matrix with current hosted runners.
Changes
actions/setup-go@v4reference in the release workflow.macos-15instead of the movingmacos-latestimage. The current macOS 26 image is incompatible with the project's existing Go 1.21.3 linker (LC_UUID). Go versions, macOS coverage, check names, Linux/Windows runners, and race tests are preserved.Default-versus-PR comparison
The latest matching default-branch Test run passed on January 16, 2026. Its logs have expired, so that historical success is not claimed as proof of compatibility with today's runner image. Current tag targets match the PR's Action pins; fresh PR failures identify the Go/macOS image mismatch rather than an invalid SHA.
Verification
Both the PR and push Test workflows passed on
417658d7e6a6a0bb7e13967584da1dca693a3fd8, including the macOS leg. Latest CI checks completed successfully. No tests were removed or weakened, and no Action was unpinned. Human review remains required.