Skip to content

pin release-drafter to SHA and align setup action versions#432

Merged
JeremyDev87 merged 1 commit intomasterfrom
fix/408-sha-pin-actions-and-align-setup-versions
Feb 16, 2026
Merged

pin release-drafter to SHA and align setup action versions#432
JeremyDev87 merged 1 commit intomasterfrom
fix/408-sha-pin-actions-and-align-setup-versions

Conversation

@JeremyDev87
Copy link
Owner

Summary

  • Pin release-drafter/release-drafter from mutable tag @v6 to commit SHA @6db134d to mitigate supply chain attack risk
  • Upgrade actions/setup-node from v6.0.0 to v6.2.0 in composite setup action to match individual workflows
  • Upgrade actions/cache from v5.0.0 to v5.0.3 in composite setup action to match individual workflows

Changes

Action Before After
release-drafter/release-drafter @v6 (mutable tag) @6db134d (SHA pinned)
actions/setup-node @2028fbc5 (v6.0.0) @6044e13b (v6.2.0)
actions/cache @a783357 (v5.0.0) @cdf6c1fa (v5.0.3)

Affected Files

  • .github/workflows/release-drafter.yml (line 16)
  • .github/actions/setup/action.yml (lines 14, 19)

Verification

  • SHA for release-drafter v6 tag confirmed via GitHub API
  • All actions/setup-node references now consistently use v6.2.0 across repo
  • All actions/cache references now consistently use v5.0.3 across repo
  • Zero mutable tag (@vN) references remaining in .github/ directory

Test Plan

  • CI workflows run successfully on this PR
  • Release drafter creates draft release on merge to master

Closes #408

Pin release-drafter/release-drafter to commit SHA for supply chain
security, and update setup composite action dependencies to match
versions used in individual workflows.

- release-drafter: @v6 → @6db134d (SHA pin)
- actions/setup-node: v6.0.0 → v6.2.0
- actions/cache: v5.0.0 → v5.0.3

Closes #408
@vercel
Copy link

vercel bot commented Feb 16, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
codingbuddy-landing Ready Ready Preview, Comment Feb 16, 2026 11:16am

@JeremyDev87 JeremyDev87 self-assigned this Feb 16, 2026
@JeremyDev87 JeremyDev87 changed the title fix(ci): pin release-drafter to SHA and align setup action versions pin release-drafter to SHA and align setup action versions Feb 16, 2026
@JeremyDev87 JeremyDev87 merged commit a3fdf0a into master Feb 16, 2026
2 checks passed
@JeremyDev87 JeremyDev87 deleted the fix/408-sha-pin-actions-and-align-setup-versions branch February 16, 2026 11:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[HIGH] Config: GitHub Actions release-drafter not SHA-pinned + setup action version mismatch

1 participant