Skip to content

ci: pin GitHub Actions to release commits - #666

Open
SidestreamSweatyPumpkin wants to merge 5 commits into
livepeer:deltafrom
sidestream-tech:fix/editorconfig-checker-gh-workflow
Open

SidestreamSweatyPumpkin wants to merge 5 commits into
livepeer:deltafrom
sidestream-tech:fix/editorconfig-checker-gh-workflow

Conversation

@SidestreamSweatyPumpkin

Copy link
Copy Markdown
Collaborator

What does this pull request do? Explain your changes. (required)

Fixes the failing "Run editorconfig checker" CI job. The workflow used the editorconfig-checker action from @main, which now installs the latest checker. Since v4.0.0, the checker no longer reads .ecrc as a config file, so the exclude list was ignored and every deployment JSON file was reported (95 errors). This PR pins all actions across all CI workflows to commits, so new releases can't break CI unexpectedly. Each action is pinned to the commit of the version it already uses, so there are no version changes.

Specific updates (required)

  • .github/workflows/test.yaml: Pinned editorconfig-checker/action-editorconfig-checker to the commit of its v2.3.0 release which still reads .ecrc, so no config changes are needed.
  • .github/workflows/test.yaml: Pinned the editorconfig job to the commit of its v4.1.1 release
  • .github/workflows/test.yaml: Pinned the remaining actions of the test job to the commits the major tags currently point to:
    • actions/checkout@v3: v3.7.0
    • actions/setup-node@v3: v3.9.1
    • codecov/codecov-action@v4: v4.6.0
  • .github/workflows/git.yaml: Pinned both actions to the commits of their existing versions:
    • actions/checkout: v2.0.0
    • 13rac1/block-fixup-merge-action: v1.1.1

How did you test each of these updates (required)

  • CI on this PR runs successfully with the pinned actions.

Does this pull request close any open issues?

No.

Checklist:

  • README and other documentation updated
    ℹ️ CI config change only, no documentation references the workflow actions.
  • All tests using yarn test pass

Copilot AI lite review requested due to automatic review settings September 28, 2026 14:37

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues remain.

Review effort: Lite
Findings: None

What changed in this PR

Pins GitHub Actions in CI workflows to immutable release commits, preserving existing versions and .ecrc compatibility.

Changes:

  • Pinned test, coverage, checkout, and editorconfig actions.
  • Pinned checkout and merge-check actions.
File Description
.github/​workflows/​test.yaml Pins testing, coverage, checkout, and editorconfig actions.
.github/​workflows/​git.yaml Pins checkout and merge-check actions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants