Skip to content

Pin write-token GitHub Actions refs - #1782

Open
alvarosanchez wants to merge 2 commits into
masterfrom
DEV-508-pin-write-token-actions
Open

alvarosanchez wants to merge 2 commits into
masterfrom
DEV-508-pin-write-token-actions

Conversation

@alvarosanchez

@alvarosanchez alvarosanchez commented May 25, 2026 •

Copy link
Copy Markdown
Member

Pins the GitHub Actions refs in the guides workflows to commit SHAs (version in a comment), and adds top-level permissions: contents: read to the gradle, manual, publish and snapshot workflows.

Checked that the changed workflows parse as YAML and that no action ref is still mutable.


✨ This message was AI-generated using gpt-5.5

Copilot AI review requested due to automatic review settings May 25, 2026 16:52
@alvarosanchez alvarosanchez added the type: improvement A minor improvement to an existing feature label May 25, 2026
@alvarosanchez
alvarosanchez force-pushed the DEV-508-pin-write-token-actions branch from ea23c4d to 96591b1 Compare May 25, 2026 16:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the repository’s GitHub Actions workflows by replacing mutable action refs (e.g., @v4, @master) with pinned commit SHAs, and by adding top-level least-privilege permissions blocks to the modified workflows.

Changes:

  • Pin actions/checkout, actions/setup-java, actions/cache, and micronaut-projects/github-pages-deploy-action to specific commit SHAs.
  • Add top-level permissions: contents: read to affected workflows.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

File Description
.github/workflows/snapshot.yml Pins action refs to SHAs and adds least-privilege top-level permissions for the snapshot test workflow.
.github/workflows/publish.yml Pins action refs to SHAs and adds top-level permissions for the publish workflow (but currently contains a misconfigured cache step).
.github/workflows/gradle.yml Pins action refs to SHAs and adds least-privilege top-level permissions for the main test workflow.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/publish.yml

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: improvement A minor improvement to an existing feature

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

3 participants