Finding
scripts/README.md (the sha-pin check description) says local (./) and self-repository ($/) references "run at the workflow commit". For $/ that holds. For a local ./ action reference inside a reusable workflow called from another repository it does not: GitHub resolves a ./ path in the runner workspace, which holds the calling repository's checkout rather than the reusable workflow's commit. That difference is why the hub's tasks use $/ for their own actions (docs/reusable-workflows.md, the hub reusable workflow item).
WORKFLOW.md's test-methodology trace paragraph makes a similar claim ("A local (./) or self-repository ($/) call carries no pin of its own and runs at the workflow commit") and should be checked for the same gap.
Suggested fix
Distinguish the two: a $/ reference resolves at the containing workflow file's commit, while a ./ reference resolves against whatever the job checked out.
Found by a local strict review on #1885, outside that pull request's diff.
Finding
scripts/README.md(thesha-pincheck description) says local (./) and self-repository ($/) references "run at the workflow commit". For$/that holds. For a local./action reference inside a reusable workflow called from another repository it does not: GitHub resolves a./path in the runner workspace, which holds the calling repository's checkout rather than the reusable workflow's commit. That difference is why the hub's tasks use$/for their own actions (docs/reusable-workflows.md, the hub reusable workflow item).WORKFLOW.md's test-methodology trace paragraph makes a similar claim ("A local (./) or self-repository ($/) call carries no pin of its own and runs at the workflow commit") and should be checked for the same gap.Suggested fix
Distinguish the two: a
$/reference resolves at the containing workflow file's commit, while a./reference resolves against whatever the job checked out.Found by a local strict review on #1885, outside that pull request's diff.