ci: pin GitHub Actions to release commits - #666
Open
SidestreamSweatyPumpkin wants to merge 5 commits into
Open
SidestreamSweatyPumpkin wants to merge 5 commits into
SidestreamSweatyPumpkin wants to merge 5 commits into
Conversation
Copilot started reviewing on behalf of
SidestreamSweatyPumpkin
September 28, 2026 14:38
View session
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No unresolved review issues remain.
Review effort: Lite
Findings: None
What changed in this PR
Pins GitHub Actions in CI workflows to immutable release commits, preserving existing versions and .ecrc compatibility.
Changes:
- Pinned test, coverage, checkout, and editorconfig actions.
- Pinned checkout and merge-check actions.
| File | Description |
|---|---|
.github/workflows/test.yaml |
Pins testing, coverage, checkout, and editorconfig actions. |
.github/workflows/git.yaml |
Pins checkout and merge-check actions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this pull request do? Explain your changes. (required)
Fixes the failing "Run editorconfig checker" CI job. The workflow used the editorconfig-checker action from
@main, which now installs the latest checker. Since v4.0.0, the checker no longer reads.ecrcas a config file, so the exclude list was ignored and every deployment JSON file was reported (95 errors). This PR pins all actions across all CI workflows to commits, so new releases can't break CI unexpectedly. Each action is pinned to the commit of the version it already uses, so there are no version changes.Specific updates (required)
.github/workflows/test.yaml: Pinnededitorconfig-checker/action-editorconfig-checkerto the commit of its v2.3.0 release which still reads.ecrc, so no config changes are needed..github/workflows/test.yaml: Pinned the editorconfig job to the commit of its v4.1.1 release.github/workflows/test.yaml: Pinned the remaining actions of the test job to the commits the major tags currently point to:actions/checkout@v3: v3.7.0actions/setup-node@v3: v3.9.1codecov/codecov-action@v4: v4.6.0.github/workflows/git.yaml: Pinned both actions to the commits of their existing versions:actions/checkout: v2.0.013rac1/block-fixup-merge-action: v1.1.1How did you test each of these updates (required)
Does this pull request close any open issues?
No.
Checklist:
README and other documentation updatedℹ️ CI config change only, no documentation references the workflow actions.
yarn testpass