fix: pin actions/checkout to SHA in pr-review.yml - #74
Conversation
Pin actions/checkout@v5 to its commit SHA (93cb6efe18208431cddfb8368fd83d5badbf9bfd) to comply with the action-pinning policy. Closes #51 Co-authored-by: Don Petry <don-petry@users.noreply.github.com>
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe ChangesGitHub Actions Pinning
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Possibly related issues
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Tip 💬 Introducing Slack Agent: The best way for teams to turn conversations into code.Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.
Built for teams:
One agent for your entire SDLC. Right inside Slack. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
Pins actions/checkout in the PR review automation workflow to a specific commit SHA to satisfy the repository’s action-pinning compliance requirement (issue #51).
Changes:
- Replace
actions/checkout@v5with a full commit SHA pin (93cb6efe18208431cddfb8368fd83d5badbf9bfd) inpr-review.yml.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: 7a4967a220b6b2abd4800f4e065d28823addbe97
Review mode: triage-approved (single reviewer)
Summary
Single-line change pinning actions/checkout@v5 to its commit SHA (93cb6efe18208431cddfb8368fd83d5badbf9bfd) in .github/workflows/pr-review.yml. This is a standard security best practice that prevents supply chain attacks via tag mutation.
Linked issue analysis
Closes #51 — a compliance finding (action-pinning / error severity) from the weekly audit flagging actions/checkout@v5 as unpinned. The fix directly addresses the finding by pinning to the exact SHA while retaining a # v5 comment for readability.
Findings
- ✅ SHA
93cb6efe18208431cddfb8368fd83d5badbf9bfdverified as the correct commit foractions/checkouttagv5 - ✅ Version comment (
# v5) retained for maintainability - ✅ No functional changes to the workflow logic
- ✅ No security concerns
CI status
| Check | Status |
|---|---|
| Claude Code | ✅ SUCCESS |
| CodeQL (actions) | ✅ SUCCESS |
| CodeQL (javascript-typescript) | ✅ SUCCESS |
| CodeQL (python) | ✅ SUCCESS |
| CodeRabbit | ✅ SUCCESS |
Reviewed automatically by the PR-review agent (single-reviewer). Reply if you need a human review.
|
Auto-rebase blocked — the base branch contains Please rebase this branch manually: |
|
Pin actions/checkout@v5 to its commit SHA (93cb6efe18208431cddfb8368fd83d5badbf9bfd) to comply with the action-pinning policy. Closes #51 Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Don Petry <don-petry@users.noreply.github.com> Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com> Co-authored-by: Gemini CLI <gemini-cli@example.com>
Pin actions/checkout@v5 to its commit SHA (93cb6efe18208431cddfb8368fd83d5badbf9bfd) to comply with the action-pinning policy. Closes #51 Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Don Petry <don-petry@users.noreply.github.com> Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com> Co-authored-by: Gemini CLI <gemini-cli@example.com>
Pin actions/checkout@v5 to its commit SHA (93cb6efe18208431cddfb8368fd83d5badbf9bfd) to comply with the action-pinning policy. Closes #51 Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Don Petry <don-petry@users.noreply.github.com> Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com> Co-authored-by: Gemini CLI <gemini-cli@example.com>
Pin actions/checkout@v5 to its commit SHA (93cb6efe18208431cddfb8368fd83d5badbf9bfd) to comply with the action-pinning policy. Closes #51 Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Don Petry <don-petry@users.noreply.github.com> Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com> Co-authored-by: Gemini CLI <gemini-cli@example.com>
Pin actions/checkout@v5 to its commit SHA (93cb6efe18208431cddfb8368fd83d5badbf9bfd) to comply with the action-pinning policy. Closes #51 Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Don Petry <don-petry@users.noreply.github.com> Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com> Co-authored-by: Gemini CLI <gemini-cli@example.com>
Pin actions/checkout@v5 to its commit SHA (93cb6efe18208431cddfb8368fd83d5badbf9bfd) to comply with the action-pinning policy. Closes #51 Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Don Petry <don-petry@users.noreply.github.com> Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com> Co-authored-by: Gemini CLI <gemini-cli@example.com>
Pin actions/checkout@v5 to its commit SHA (93cb6efe18208431cddfb8368fd83d5badbf9bfd) to comply with the action-pinning policy. Closes #51 Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Don Petry <don-petry@users.noreply.github.com> Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com> Co-authored-by: Gemini CLI <gemini-cli@example.com>
Pin actions/checkout@v5 to its commit SHA (93cb6efe18208431cddfb8368fd83d5badbf9bfd) to comply with the action-pinning policy. Closes #51 Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Don Petry <don-petry@users.noreply.github.com> Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com> Co-authored-by: Gemini CLI <gemini-cli@example.com>



Summary
actions/checkout@v5to its commit SHA93cb6efe18208431cddfb8368fd83d5badbf9bfdin.github/workflows/pr-review.ymlaction-pinningcompliance finding from the weekly auditCloses #51
Generated with Claude Code
Summary by CodeRabbit