Add the tool that pins actions, and a Dependabot file to keep them moving - #10
Merged
Merged
Conversation
…ving A tag is a label somebody else can move, and every workflow in this organisation took one on trust. `pypa/gh-action-pypi-publish@release/v1` was a branch -- it moves by design -- on the step that publishes to PyPI. pin_actions.py resolves each reference through the API and rewrites it as a commit with the tag kept as a trailing comment, which is the form Dependabot understands: it raises the commit and the comment together. Only successes are cached, because one timed-out request would otherwise decide that an action is unresolvable for the rest of a run, and the same reference appears dozens of times in a repository. This repository had no Dependabot file while it had no workflows. It has three now, and pinned actions are only maintainable if something raises them.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
scripts/pin_actions.pyrewrites everyuses: owner/repo@tagas a commit, keeping the tag as a trailing comment — the form Dependabot maintains.Why it matters here: a tag is a label somebody else can move, and these workflows run with a token that can write.
pypa/gh-action-pypi-publish@release/v1was a branch on the step that publishes to PyPI.Also adds
.github/dependabot.yml— this repository had none while it had no workflows, and it now has three. Pinned actions are only maintainable if something raises them.Modes:
--dry-run,--check(exit 1 if anything is unpinned, for CI), and the default rewrite. Only successful resolutions are cached, deliberately — see the docstring.First applied to stadion in DrobyshevDev/stadion#8; the rest follow once that is green.