Skip to content

fix(ci): validate composite action pins against registry - #4103

Merged
Ricky Gummadi (Ricky-G) merged 2 commits into
mainfrom
ricky-g-composite-action-pinning
Sep 23, 2026
Merged

Ricky Gummadi (Ricky-G) merged 2 commits into
mainfrom
ricky-g-composite-action-pinning

Conversation

@Ricky-G

@Ricky-G Ricky Gummadi (Ricky-G) commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Validate and synchronize composite-action references in .github/actions against .github/ci/actions.toml, preventing the silent drift reported in #3366. Closes #3366.

Supersedes #3367, which was closed without merging.

Problem

The CI generation check only regenerated generated workflows, so pinned actions inside local composite actions could drift from the registry without failing CI.

Changes

File What changed
.github/actions/ai-agent-runner/action.yml Sync actions/setup-node with the registry pin.
.github/actions/contributor-check/action.yml Sync actions/setup-python with the registry pin.
.github/ci/actions.toml Clarify that the registry covers local composite actions.
.github/workflows/ci-generation-check.yml Run the guard when .github/actions/** changes.
scripts/ci/generate_workflows.py Detect drift and unregistered remote action references in --check; synchronize registered pins in --write.
tests/ci/test_generate_workflows.py Cover drift detection, pin synchronization, and rejection of unregistered references.

Testing

  • python scripts/ci/generate_workflows.py --check — passed.
  • python -m pytest tests/ci/test_generate_workflows.py -q — 16 passed after the review fix.
  • Modified YAML files parsed successfully with yaml.safe_load.
  • python -m pytest tests/ci -q — 99 passed, 6 skipped, 4 failed on this Windows host: three tests require /bin/bash, and one existing test expects POSIX path separators.
  • Ruff is not installed on the host. The pinned cspell package could not be fetched because package downloads are disabled in this environment; the flagged readlines() call has been replaced with read().splitlines(keepends=True).

@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions github-actions Bot added the size/L Large PR (< 500 lines) label Sep 23, 2026
@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • PR body: the design, helper names (_composite_action_files, _registry_by_action_name, check_composite_action_pins, sync_composite_action_pins) and the test fixtures follow #3367 (qubeena07, closed 09-13 for an unaddressed sequencing ask that main has since resolved). Add "Supersedes #3367" to the body and Co-authored-by: qubeena07 <qubeena7@gmail.com> to the commit.

Comment thread scripts/ci/generate_workflows.py Outdated
Comment thread .github/actions/ai-agent-runner/action.yml
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com>
Co-authored-by: qubeena07 <qubeena7@gmail.com>
@Ricky-G
Ricky Gummadi (Ricky-G) force-pushed the ricky-g-composite-action-pinning branch from b97493f to 200f345 Compare September 23, 2026 20:02
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com>

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving at 07ae528. The spell-check word is gone (splitlines(keepends=True)), the body names #3367 and the commit credits qubeena07, and the checker still discriminates on all six mutations (stale SHA, changed version comment, unregistered action, --write restore, quoted uses, CRLF round-trip). Both v7.0.0 pins resolve to their tags and every consumer matches the registry byte for byte. CI green.

For the record: the composites run on pull_request_target against the base, so the v7 setup-node and setup-python pins first execute on main after this merges. Watch the first AI PR Review and Contributor Reputation Check runs; if setup-node warns about package-manager-cache, set it to false.

@Ricky-G
Ricky Gummadi (Ricky-G) merged commit 5315ada into main Sep 23, 2026
141 checks passed
@Ricky-G
Ricky Gummadi (Ricky-G) deleted the ricky-g-composite-action-pinning branch September 23, 2026 20:38
Yuvraj Singh (yuvrajsingh2428) pushed a commit to yuvrajsingh2428/agent-governance-toolkit that referenced this pull request Oct 1, 2026
)

* fix(ci): enforce registry pins for composite actions

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com>
Co-authored-by: qubeena07 <qubeena7@gmail.com>

* fix(ci): recognize splitlines keepends in spell check

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com>

---------

Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: qubeena07 <qubeena7@gmail.com>
Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

scripts/ci/cd size/L Large PR (< 500 lines) tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

composite actions in .github/actions are not covered by the actions.toml pin registry and have already drifted

2 participants