Skip to content

Pin GitHub Actions to full-length commit SHAs - #6409

Merged
Stephan T. Lavavej (StephanTLavavej) merged 3 commits into
microsoft:mainfrom
danfiedler-msft:danfiedler/pin-actions
Aug 24, 2026
Merged

Pin GitHub Actions to full-length commit SHAs#6409
Stephan T. Lavavej (StephanTLavavej) merged 3 commits into
microsoft:mainfrom
danfiedler-msft:danfiedler/pin-actions

Conversation

@danfiedler-msft

Copy link
Copy Markdown
Contributor

Summary

This PR pins GitHub Actions to full-length commit SHAs for improved security and reproducibility and adds a 7 day cooldown to Dependabot configuration for GitHub Actions. This work is described in more detail at https://aka.ms/action-pinning.

Why?

Pinning actions to commit SHAs prevents supply-chain attacks where a tag could be moved to point to malicious code. This is a recommended security best practice per the GitHub Actions security hardening guide.

This change mitigates the risk of tag retargeting to malicious code as seen in incidents like the tj-actions/changed-files action compromise or codfish/semantic-release-action compromise and improves the integrity and reproducibility of the CI/CD pipeline.

What changed?

Action pinning: Third-party action references in .github/workflows/ that used mutable tag-based references (e.g., actions/checkout@v4) have been updated to full-length commit SHAs with a version comment (e.g., actions/checkout@<sha> # v4) using the pinact tool. References that were already pinned to a SHA, or that used immutable release tags, were left unchanged.

Dependabot configuration: .github/dependabot.yml has been updated to ensure a github-actions package-ecosystem section is present with a cooldown configuration (default-days: 7). If the file did not exist, it was created. If a github-actions section already existed, only the cooldown block was added or its default-days value was increased to 7 if it was lower. The 7-day cooldown provides a window for the community to detect and report compromised releases before they are automatically proposed as updates, reducing exposure to supply-chain attacks via newly published malicious versions.

Is this safe to merge?

Yes. The pinned SHAs correspond to the same commits that the existing tags pointed to. No behavioral changes in action execution are introduced. You can verify the pinned SHA value using the GitHub REST API (e.g., the commit hash for actions/checkout@v7 can be found in the sha property in the JSON response for GET https://api.github.com/repos/actions/checkout/commits/v7).

Additional Information

For more information, please see https://aka.ms/action-pinning

@danfiedler-msft
Dan Fiedler (danfiedler-msft) requested a review from a team as a code owner August 21, 2026 19:40
Copilot AI balanced review requested due to automatic review settings August 21, 2026 19:40
@github-project-automation github-project-automation Bot moved this to Initial Review in STL Code Reviews Aug 21, 2026
@azure-pipelines

This comment was marked as resolved.

This comment was marked as resolved.

@StephanTLavavej

This comment was marked as resolved.

@StephanTLavavej Stephan T. Lavavej (StephanTLavavej) added the infrastructure Related to repository automation label Aug 21, 2026
@azure-pipelines

This comment was marked as resolved.

@StephanTLavavej Stephan T. Lavavej (StephanTLavavej) moved this from Initial Review to Ready To Merge in STL Code Reviews Aug 21, 2026
Copilot AI review requested due to automatic review settings August 21, 2026 20:08

This comment was marked as resolved.

@StephanTLavavej

Copy link
Copy Markdown
Member

Thanks! We merge PRs to our GitHub and MSVC-internal repos simultaneously in a semi-manual process, batched up to save time. Your PR will be part of the next batch. I'll post comments as I prepare your PR for merging; no action is required from you.

@StephanTLavavej

This comment was marked as resolved.

@azure-pipelines

This comment was marked as resolved.

@muellerj2

Copy link
Copy Markdown

.github/dependabot.yml has been updated to ensure a github-actions package-ecosystem section is present with a cooldown configuration (default-days: 7). If the file did not exist, it was created. If a github-actions section already existed, only the cooldown block was added or its default-days value was increased to 7 if it was lower. The 7-day cooldown provides a window for the community to detect and report compromised releases before they are automatically proposed as updates, reducing exposure to supply-chain attacks via newly published malicious versions.

You are probably aware, but for the record: This statement is not completely true. Dependabot happily ignores the 7-day cooldown for automatically created security update PRs as documented:

The cooldown option is only available for version updates, not security updates.

So Dependabot might still create update PRs for new releases less than 7 days old if automatic security updates are turned on for the repository and Dependabot considers a version bump a security update.

@StephanTLavavej

Copy link
Copy Markdown
Member

I'm mirroring this to the MSVC-internal repo. Please notify me if any further changes are pushed, otherwise no action is required.

@StephanTLavavej Stephan T. Lavavej (StephanTLavavej) moved this from Ready To Merge to Merging in STL Code Reviews Aug 24, 2026
@StephanTLavavej
Stephan T. Lavavej (StephanTLavavej) merged commit c3c5f3d into microsoft:main Aug 24, 2026
48 checks passed
@github-project-automation github-project-automation Bot moved this from Merging to Done in STL Code Reviews Aug 24, 2026
@StephanTLavavej

Copy link
Copy Markdown
Member

Thanks for improving our infrastructure security! 😻 🛡️ 🔒

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

infrastructure Related to repository automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants