Repository navigation
fix(ci): validate composite action pins against registry - #4103
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
MohammadHaroonAbuomar
left a comment
There was a problem hiding this comment.
- PR body: the design, helper names (
_composite_action_files,_registry_by_action_name,check_composite_action_pins,sync_composite_action_pins) and the test fixtures follow #3367 (qubeena07, closed 09-13 for an unaddressed sequencing ask that main has since resolved). Add "Supersedes #3367" to the body andCo-authored-by: qubeena07 <qubeena7@gmail.com>to the commit.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com> Co-authored-by: qubeena07 <qubeena7@gmail.com>
b97493f to
200f345
Compare
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com>
MohammadHaroonAbuomar
left a comment
There was a problem hiding this comment.
Approving at 07ae528. The spell-check word is gone (splitlines(keepends=True)), the body names #3367 and the commit credits qubeena07, and the checker still discriminates on all six mutations (stale SHA, changed version comment, unregistered action, --write restore, quoted uses, CRLF round-trip). Both v7.0.0 pins resolve to their tags and every consumer matches the registry byte for byte. CI green.
For the record: the composites run on pull_request_target against the base, so the v7 setup-node and setup-python pins first execute on main after this merges. Watch the first AI PR Review and Contributor Reputation Check runs; if setup-node warns about package-manager-cache, set it to false.
) * fix(ci): enforce registry pins for composite actions Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com> Co-authored-by: qubeena07 <qubeena7@gmail.com> * fix(ci): recognize splitlines keepends in spell check Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com> --------- Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: qubeena07 <qubeena7@gmail.com> Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Summary
Validate and synchronize composite-action references in
.github/actionsagainst.github/ci/actions.toml, preventing the silent drift reported in #3366. Closes #3366.Supersedes #3367, which was closed without merging.
Problem
The CI generation check only regenerated generated workflows, so pinned actions inside local composite actions could drift from the registry without failing CI.
Changes
.github/actions/ai-agent-runner/action.ymlactions/setup-nodewith the registry pin..github/actions/contributor-check/action.ymlactions/setup-pythonwith the registry pin..github/ci/actions.toml.github/workflows/ci-generation-check.yml.github/actions/**changes.scripts/ci/generate_workflows.py--check; synchronize registered pins in--write.tests/ci/test_generate_workflows.pyTesting
python scripts/ci/generate_workflows.py --check— passed.python -m pytest tests/ci/test_generate_workflows.py -q— 16 passed after the review fix.yaml.safe_load.python -m pytest tests/ci -q— 99 passed, 6 skipped, 4 failed on this Windows host: three tests require/bin/bash, and one existing test expects POSIX path separators.readlines()call has been replaced withread().splitlines(keepends=True).