Skip to content

Pin GitHub Actions to full-length commit SHAs - #6182

Merged
Bogdan Gavril (bgavrilMS) merged 1 commit into
AzureAD:mainfrom
danfiedler-msft:danfiedler/pin-actions
Sep 15, 2026
Merged

Bogdan Gavril (bgavrilMS) merged 1 commit into
AzureAD:mainfrom
danfiedler-msft:danfiedler/pin-actions

Conversation

@danfiedler-msft

@danfiedler-msft Dan Fiedler (danfiedler-msft) commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

Summary

This PR pins GitHub Actions to full-length commit SHAs for improved security and reproducibility and adds a 7 day cooldown to Dependabot configuration for GitHub Actions. This work is described in more detail at https://aka.ms/action-pinning.

Why?

Pinning actions to commit SHAs prevents supply-chain attacks where a tag could be moved to point to malicious code. This is a recommended security best practice per the GitHub Actions security hardening guide.

This change mitigates the risk of tag retargeting to malicious code as seen in incidents like the tj-actions/changed-files action compromise or codfish/semantic-release-action compromise and improves the integrity and reproducibility of the CI/CD pipeline.

What changed?

Action pinning: Third-party action references in .github/workflows/ that used mutable tag-based references (e.g., actions/checkout@v4) have been updated to full-length commit SHAs with a version comment (e.g., actions/checkout@<sha> # v4) using the pinact tool. References that were already pinned to a SHA, or that used immutable release tags, were left unchanged.

Dependabot configuration: .github/dependabot.yml has been updated to ensure a github-actions package-ecosystem section is present with a cooldown configuration (default-days: 7). If the file did not exist, it was created. If a github-actions section already existed, only the cooldown block was added or its default-days value was increased to 7 if it was lower. The 7-day cooldown provides a window for the community to detect and report compromised releases before they are automatically proposed as updates, reducing exposure to supply-chain attacks via newly published malicious versions.

Is this safe to merge?

Yes. The pinned SHAs correspond to the same commits that the existing tags pointed to. No behavioral changes in action execution are introduced. You can verify the pinned SHA value using the GitHub REST API (e.g., the commit hash for actions/checkout@v7 can be found in the sha property in the JSON response for GET https://api.github.com/repos/actions/checkout/commits/v7).

Additional Information

For more information, please see https://aka.ms/action-pinning

assistance: agentic-mixed
type: security
agent-tool: copilot-cli
agent-model: gpt-5.6-sol
work-item: AB#n/a

Copilot AI lite review requested due to automatic review settings September 6, 2026 01:30

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The changes are limited to action SHA pinning and a valid Dependabot configuration addition, with no functional workflow logic modifications.

Pull request overview

This PR hardens the repository’s CI/CD posture by pinning GitHub Actions to immutable full-length commit SHAs (reducing tag-retargeting supply-chain risk) and by adding a Dependabot configuration that introduces a 7-day update cooldown for GitHub Actions.

Changes:

  • Updated multiple workflows under .github/workflows/ to replace tag-based uses: references with full-length commit SHAs (retaining version comments for readability).
  • Added .github/dependabot.yml to enable grouped GitHub Actions updates on a weekly schedule with a 7-day cooldown window.
File summaries
File Description
.github/workflows/spellcheck.yml Pins actions/checkout and annotates the existing pinned codespell action with a version comment.
.github/workflows/RunIssueSentinel.yml Pins Azure/issue-sentinel to a full commit SHA with a version comment.
.github/workflows/label-issues.yml Pins actions/github-script invocations to a full commit SHA with a version comment.
.github/workflows/benchmark-action.yml Pins actions/setup-dotnet and actions/cache to full commit SHAs with version comments.
.github/workflows/auto-answer-issues.yml Pins actions/checkout and actions/setup-node to full commit SHAs with version comments.
.github/dependabot.yml Adds Dependabot configuration for github-actions with weekly cadence, grouping, and a 7-day cooldown.
Review details
  • Files reviewed: 6/6 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved review comments; the changes improve action supply-chain security.

Review details
  • Files reviewed: 6/6 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved issues were identified, and all reviewed changes support the stated security goals.

Review details
  • Files reviewed: 6/6 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agentic-mixed Agent changes with meaningful human-authored edits security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants