Skip to content

Update github-actions - #4032

Merged
jiridanek merged 1 commit into
mainfrom
konflux/mintmaker/main/github-actions
Jul 9, 2026
Merged

jiridanek merged 1 commit into
mainfrom
konflux/mintmaker/main/github-actions

Conversation

@ide-developer

@ide-developer ide-developer commented Jul 9, 2026 •

Copy link
Copy Markdown
Collaborator

This PR contains the following updates:

Package Type Update Change
actions/cache action minor v6.0.0 → v6.1.0
actions/setup-go action minor v6.4.0 → v6.5.0
actions/setup-python action minor v6.2.0 → v6.3.0
actions/stale action minor v10.2.0 → v10.3.0
aquasecurity/trivy uses-with minor v0.70.0 → v0.72.0
astral-sh/setup-uv action minor v8.1.0 → v8.3.2
docker/build-push-action action minor v7.2.0 → v7.3.0
docker/login-action action minor v4.1.0 → v4.4.0
docker/setup-buildx-action action minor v4.1.0 → v4.2.0
github/codeql-action action minor v4.35.4 → v4.37.0
golangci/golangci-lint-action action minor v9.2.0 → v9.3.0
jdx/mise-action action minor v4.0.1 → v4.2.0
pnpm/action-setup action patch v6.0.8 → v6.0.9
snok/container-retention-policy action minor v3.0.1 → v3.1.0

Release Notes

actions/cache (actions/cache)

v6.1.0

Compare Source

What's Changed

Full Changelog: actions/cache@v6...v6.1.0

actions/setup-go (actions/setup-go)

v6.5.0

Compare Source

What's Changed
Dependency update
New Contributors

Full Changelog: actions/setup-go@v6...v6.5.0

actions/setup-python (actions/setup-python)

v6.3.0

Compare Source

What's Changed

Enhancement
Dependency update
Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

actions/stale (actions/stale)

v10.3.0

Compare Source

What's Changed

Bug Fix
Dependency Updates

New Contributors

Full Changelog: actions/stale@v10...v10.3.0

aquasecurity/trivy (aquasecurity/trivy)

v0.72.0

Compare Source

⚡ Highlights ⚡

👉 https://github.com/aquasecurity/trivy/discussions/10907

Changelog

https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0720-2026-06-30

v0.71.2

Compare Source

Changelog

v0.71.1

Compare Source

Changelog

  • 164b383 release: v0.71.1 [release/v0.71] (#​10818)
  • a72d9a4 fix(oci): validate artifact filename
  • 3dd9847 fix: forward ospkg detector options through ospkg.NewScanner [backport: release/v0.71] (#​10825)
  • a62cbe4 fix(vex): load VEX documents from within the repository directory [backport: release/v0.71] (#​10821)
  • 43d1d26 fix: surface the original analysis error instead of context cancellation [backport: release/v0.71] (#​10812)
  • ac7696c ci: expect GitHub App bot as backport PR author [backport: release/v0.71] (#​10815)

v0.71.0

Compare Source

⚡ Highlights ⚡

👉 https://github.com/aquasecurity/trivy/discussions/10767

Changelog

https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0710-2026-06-01

astral-sh/setup-uv (astral-sh/setup-uv)

v8.3.2: 🌈 update known checksums for 0.11.28

Compare Source

Changes

Just a maintenance release

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

v8.3.1: 🌈 update known checksums for 0.11.27

Compare Source

Changes

Just a maintenance release

🧰 Maintenance

📚 Documentation

v8.3.0: 🌈 Support uv.lock as a version-file source

Compare Source

Changes

Thanks to @​somaz94 you can now use the pinned version of uv itself in uv.lock. It gets picked up automatically.
If you have pinned another version of uv in your uv.lock you can use the inputs version or version-source to override this.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

v8.2.0: 🌈 New inputs quiet and download-from-astral-mirror

Compare Source

Changes

This release brings two new inputs and a few bug fixes.

New inputs

Lets talk about the new inputs first.

quiet

Pretty simple. It turns of all info loggings. Useful if you use this in a composite action and are not interested in all the details.
In the upcoming releases we will add log groups to fully implement support for "less noise"

[!NOTE]
Warnings and errors are always logged.

download-from-astral-mirror

In some cases you may want to directly use the fallback of checking for available versions and downloading releases from GitHub instead of using the astral.sh mirror. Setting download-from-astral-mirror: false allows you to do that.

Bugfixes

When using the astral.sh mirror to query available versions and download releases (done by default) we now stop sending the GitHub token in the header. The mirror never looked at it but we shouldn't be handing out that data even if it is just a short lived token.
All other bugfixes try to limit the impact of failed GitHub queries due to retries and other faults.

We couldn't pinpoint all rootcauses yet but added more logging for error cases to track them down.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

⬆️ Dependency updates

docker/build-push-action (docker/build-push-action)

v7.3.0

Compare Source

Full Changelog: docker/build-push-action@v7.2.0...v7.3.0

docker/login-action (docker/login-action)

v4.4.0

Compare Source

Full Changelog: docker/login-action@v4.3.0...v4.4.0

v4.3.0

Compare Source

Full Changelog: docker/login-action@v4.2.0...v4.3.0

v4.2.0

Compare Source

Full Changelog: docker/login-action@v4.1.0...v4.2.0

docker/setup-buildx-action (docker/setup-buildx-action)

v4.2.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.1.0...v4.2.0

github/codeql-action (github/codeql-action)

v4.37.0

Compare Source

  • Update default CodeQL bundle version to 2.26.0. #​3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@​ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #​3973

v4.36.3

Compare Source

No user facing changes.

v4.36.2

Compare Source

  • Cache CodeQL CLI version information across Actions steps. #​3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #​3937
  • Update default CodeQL bundle version to 2.25.6. #​3948

v4.36.1

Compare Source

No user facing changes.

v4.36.0

Compare Source

  • Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #​3894
  • Add support for SHA-256 Git object IDs. #​3893
  • Update default CodeQL bundle version to 2.25.5. #​3926

v4.35.5

Compare Source

  • We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #​3899
  • For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #​3791
  • If multiple inputs are provided for the GitHub-internal analysis-kinds input, only code-scanning will be enabled. The analysis-kinds input is experimental, for GitHub-internal use only, and may change without notice at any time. #​3892
  • Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #​3880
golangci/golangci-lint-action (golangci/golangci-lint-action)

v9.3.0

Compare Source

What's Changed

Changes
Dependencies

Full Changelog: golangci/golangci-lint-action@v9.2.1...v9.3.0

v9.2.1

Compare Source

What's Changed

IMPORTANT: this is the first immutable release.

Changes
Dependencies

Full Changelog: golangci/golangci-lint-action@v9.2.0...v9.2.1

jdx/mise-action (jdx/mise-action)

v4.2.0: : Bootstrap mode & wget fallback

Compare Source

This release adds an opt-in bootstrap mode for projects that use mise bootstrap, and makes the action work on runner images that ship wget but not curl.

Added

Bootstrap mode (#​522) by @​jdx

Three new inputs let the action drive mise bootstrap instead of mise install:

- uses: jdx/mise-action@v4
  with:
    bootstrap: true
    bootstrap_skip: "tools,task"   # comma-separated parts to skip
    bootstrap_args: "--yes"        # extra args forwarded to mise bootstrap
  • When bootstrap: true, the action runs mise bootstrap under the existing install gate and sets MISE_EXPERIMENTAL=1 automatically.
  • If a repo mise lock file is present, it runs mise --locked bootstrap, matching the auto-lock behavior introduced for mise install in v4.1.0.
  • install_args cannot be combined with bootstrap: true — the action fails fast and tells you to use bootstrap_skip / bootstrap_args instead, because full bootstrap doesn't support partial tool install args.
  • A new {{bootstrap_hash}} template variable is included in the default cache key (and available in custom cache_key templates) so bootstrap and non-bootstrap configurations don't share caches.

bootstrap_skip relies on mise bootstrap --skip from jdx/mise#10497, so make sure you're on a recent mise version if you use it.

Fixed

  • Fall back to wget when curl is unavailable (#​521) by @​risu729 — The action used to hard-code curl for fetching the mise binary, tar/zip archives, and the latest VERSION lookup, which broke on minimal runner images that only ship wget. It now prefers curl and transparently falls back to wget, preserving the streaming download | tar fast path for .tar.gz and .tar.zst installs on Linux/macOS. Proxy support is unchanged — both tools honor HTTP_PROXY/HTTPS_PROXY. Addresses jdx/mise#10488.

Documentation

Full Changelog: jdx/mise-action@v4.1.0...v4.2.0

v4.1.0: : automatic --locked installs

Compare Source

This release adds automatic locked installs when a mise.lock is present, and fixes a long-standing cache-key collision that could poison tool installs when workflows migrate between runner providers.

Added

Automatic --locked install when mise.lock exists (#​495) by @​zeitlinger

When a repo contains mise.lock, the action now automatically passes --locked to mise install (on mise versions that support it). This removes the need to manually set install_args: --locked and prevents mise install from silently mutating the lockfile in CI. Explicit install_args and older mise versions are still respected.

Note: workflows with a stale lockfile may now fail earlier and more explicitly instead of silently updating mise.lock mid-run — this surfaces lockfile drift rather than hiding it.

Fixed

  • Cache key collisions across runner providers (#​456) — the default cache key now includes the runner image (e.g. macos15, ubuntu24 for GitHub-hosted runners; self-hosted otherwise). Previously, repos migrating between providers like github-hosted, namespace.so, BuildJet, and self-hosted runners with the same OS/arch could restore a peer provider's ~/.local/share/mise/installs/*, causing failures like does not have an executable named '…' or SIGILL crashes from binaries built against a different glibc/CPU featureset. Expect a one-time cache miss after upgrading; thereafter the cache stays scoped per image.
  • mise-shim.exe missing on Windows (#​476) by @​risu729 — the action now installs mise-shim.exe alongside mise.exe and repairs restored caches that lack the shim. Fixes #​475.

Changed

  • Migrated the bundled action build from ncc (CommonJS) to Rollup (ESM) (#​436). No user-facing behavior change.

Full Changelog: jdx/mise-action@v4.0.1...v4.1.0

pnpm/action-setup (pnpm/action-setup)

v6.0.9

Compare Source

What's Changed

Full Changelog: pnpm/action-setup@v6...v6.0.9

snok/container-retention-policy (snok/container-retention-policy)

v3.1.0

Compare Source

Features

  • The action now automatically detects and filters out any package version that belongs to a multi-arch image meant to be retained (#​131). This should resolve issues #​90, #​95, #​97 and more. Thanks to @​sennerholm for starting this work.

Fixes

  • Fixed an issue in negative durations causing the action to panic (#​133). Fixes #​128.
  • Fixed token parsing related to Github's token format migration (source). Fixes #​132 and #​129.

Misc

  • Updated all workflow versions
  • Updated dependencies and linters

Full Changelog: snok/container-retention-policy@v3.0.1...v3.1.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

Summary by CodeRabbit

  • Chores
    • Updated several automation and CI tools to newer versions, including build, test, release, and maintenance workflows.
    • Refreshed security scanning and reporting components to keep scans and uploads current.
    • Improved workflow reliability and consistency by pinning newer approved action revisions across the repository.

Signed-off-by: ide-developer <rhoai-ide-konflux@redhat.com>
@openshift-ci
openshift-ci Bot requested review from atheo89 and ayush17 July 9, 2026 13:49
@github-actions github-actions Bot added the review-requested GitHub Bot creates notification on #pr-review-ai-ide-team slack channel label Jul 9, 2026
@openshift-ci openshift-ci Bot added the size/m label Jul 9, 2026
@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

No new commits to review since the last review.

⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited), Repository UI (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 6b0d6674-9bd2-47eb-a114-20d09e06aeb0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • ✅ Review completed - (🔄 Check again to review again)
📝 Walkthrough

Walkthrough

Pinned commit SHAs/version tags for third-party GitHub Actions are bumped across 21 workflow/action files: docker/login-action (v4.1.0→v4.4.0), docker/setup-buildx-action (v4.1.0→v4.2.0), docker/build-push-action (v7.2.0→v7.3.0), astral-sh/setup-uv (v8.1.0→v8.3.2), actions/setup-go (v6.4.0→v6.5.0), golangci-lint-action (v9.2.0→v9.3.0), actions/cache (v6.0.0→v6.1.0), github/codeql-action (v4.35.4→v4.37.0), actions/setup-python (v6.2.0→v6.3.0), trivy-action (v0.70.0→v0.72.0), actions/stale (v10.2.0→v10.3.0), snok/container-retention-policy (v3.0.1→v3.1.0), jdx/mise-action (v4.0.1→v4.2.0), and pnpm/action-setup (v6.0.8→v6.0.9). No workflow logic, inputs, or job structure changed.

Estimated code review effort: 2 (Simple) | ~10 minutes

Supply-chain note: every entry is a SHA-pinned bump — verify each new commit SHA resolves to the claimed tag/release upstream before merge (CWE-829: Inclusion of Functionality from Untrusted Control Sphere). Confirm no unpinned @vX floating tags were reintroduced anywhere in this diff.

🚥 Pre-merge checks | ✅ 9 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Description check ⚠️ Warning Required template sections are missing: Description, How Has Been Tested, checklist, and merge criteria. Fill in the template sections with the change details, testing performed, checklist marks, and merge criteria.
Title check ❓ Inconclusive Title is imperative but too generic; it doesn't identify the workflows or actions changed. Rename it to a specific imperative title, e.g. "NO-JIRA: ci: bump GitHub Actions pins".
✅ Passed checks (9 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Branch Prefix Policy ✅ Passed HEAD subject is 'Update github-actions'; on base main, policy forbids branch prefixes only, so the title is compliant.
Contribution Quality And Spam Detection ✅ Passed Renovate action-pin refresh across workflow files; templated body alone doesn’t meet the 2-signal threshold, and there’s no security-theater or code-quality defect.
No Hardcoded Secrets ✅ Passed Added lines are only action pins/version bumps; no new hardcoded creds, embedded user:pass URLs, or secret-like literals (CWE-798).
No Weak Cryptography ✅ Passed PASS: touched workflows only bump action pins; no MD5/SHA1/DES/RC4/ECB, custom crypto, or secret-compare code found (CWE-327/CWE-916).
No Injection Vectors ✅ Passed Diff only bumps pinned action refs/version strings; no added SQL/shell/eval/yaml.load/innerHTML sinks or user-controlled interpolation (CWE-78/89/94/502/79).
No Privileged Containers ✅ Passed No Kubernetes/OpenShift, Helm, or Dockerfile changes; only GitHub Actions pins updated, with no privileged settings or CWE-250/CWE-266 signals.
No Sensitive Data In Logs ✅ Passed Only action/version pin bumps; no added echo/core.info/warning of passwords, tokens, PII, or raw bodies. CWE-532/CWE-200 not introduced.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 39.70%. Comparing base (3d53de6) to head (cea7bd2).
✅ All tests successful. No failed tests found.

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##             main    #4032   +/-   ##
=======================================
  Coverage   39.70%   39.70%           
=======================================
  Files          43       43           
  Lines        5374     5374           
  Branches      913      913           
=======================================
  Hits         2134     2134           
  Misses       3038     3038           
  Partials      202      202           
Flag Coverage Δ
python 39.70% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 3d53de6...cea7bd2. Read the comment docs.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@openshift-ci openshift-ci Bot added size/m and removed size/m labels Jul 9, 2026
@jiridanek

Copy link
Copy Markdown
Member

@coderabbitai any exciting new features or worrisome changes in the updated actions?

@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown
Contributor
🧩 Analysis chain

🤖 web_search executed:

docker/login-action v4.4.0 release notes changelog security fix

Length of output: 7462


🤖 web_search executed:

github/codeql-action v4.37.0 changelog CodeQL bundle security

Length of output: 8475


🤖 web_search executed:

aquasecurity/trivy-action v0.72.0 release notes CVE

Length of output: 9163


🤖 web_search executed:

snok/container-retention-policy v3.1.0 changelog fix

Length of output: 7408


🤖 web_search executed:

actions/stale v10.3.0 release notes changes

Length of output: 9574


@jiridanek

CVE-2026-33634 (Trivy supply-chain compromise) — relevant to this PR since aquasecurity/trivy is bumped to v0.72.0. Recap: a threat actor used compromised credentials to publish a malicious trivy v0.69.4, force-pushed 76/77 tags of aquasecurity/trivy-action, and replaced all aquasecurity/setup-trivy tags with credential-stealing malware (continuation of the Feb 2026 incident). Affected: trivy binary 0.69.4, trivy-action 0.0.1–0.34.2, setup-trivy 0.2.0–0.2.6 (pre-recreation). v0.72.0 postdates all of that, so this PR is not pulling a compromised release. Mitigating factor: this repo pins the action by full commit SHA (not a mutable tag), which is exactly CISA's stated mitigation (BOD 22-01 guidance references this incident) — tag-mutation attacks like this one don't affect SHA-pinned consumers. Verify the pinned SHA in .github/workflows/security.yaml actually resolves to the tagged v0.72.0 commit and not something force-pushed after the fact; don't trust the version comment alone.

github/codeql-action v4.37.0 — bumps default CodeQL bundle to 2.26.0. Also ships (not yet enabled) support for a new config-file input format: [owner/]repo[@ref][:path], allowing init to fetch config from an arbitrary remote repo/ref. This is a new remote-code-influence surface once enabled — if anyone later sets config-file to a cross-org repo, that repo's maintainers gain influence over your CodeQL query configuration (CWE-829: Inclusion of Functionality from Untrusted Control Sphere). Not exploitable today since this repo doesn't set config-file, but worth flagging before anyone adopts it.

docker/login-action v4.4.0 — cosmetic/dependency fix only (skips masking an empty registry-auth secret, bumps @aws-sdk/client-ecr*). No CVE.

actions/stale v10.3.0 — bug fix to ignore stale-labeling events as activity triggers, plus dependency bumps (@actions/core, @octokit/plugin-retry). No CVE in this diff; note a prior form-data critical vuln fix landed in an earlier v10.x release, already covered.

snok/container-retention-policy v3.1.0 — fixes a panic on negative durations (DoS-adjacent, not exploitable remotely) and fixes GHCR token parsing broken by GitHub's token-format migration — this is a correctness fix, not hardening. Also adds multi-arch manifest protection so children of multi-arch images you intend to keep aren't pruned. No CVE.

Net assessment: nothing in this bump set introduces a new CVE into the pinned SHAs. The one item requiring your attention going forward is the CodeQL config-file remote-fetch capability — don't enable it against untrusted/third-party repos. Confirm SHA-pinning discipline is maintained on every future Renovate bump, since that's the control that neutralizes tag-hijack attacks like CVE-2026-33634.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@jiridanek

jiridanek commented Jul 9, 2026 •

Copy link
Copy Markdown
Member

@coderabbitai I read through the PR description (Renovate changelog + CodeRabbit review) and cross-checked the actual diff. Here's what stands out.

What's in the PR

14 packages bumped across 21 workflow/action files — all uses: refs stay SHA-pinned (only the version comment changes), consistent with repo policy. Notably golangci/golangci-lint-action → v9.3.0 with version: v2.12.2 unchanged in code-quality.yaml — confirms the RHAIENG-6163 fix is holding (no digest-pin attempt on that value).

Things to be mindful of

1. github/codeql-action v4.35.4 → v4.37.0 (used in codeql.yaml, gitleaks.yaml, semgrep.yaml, security.yaml)
v4.36.0 has a breaking change: bumps the minimum required CodeQL bundle version to 2.19.4. Since none of these workflows pin an explicit bundle version, this should be transparent — but if any CodeQL Analysis job fails post-merge with a bundle-version error, this is the first place to look.

2. aquasecurity/trivy v0.70.0 → v0.72.0 (security.yaml, via uses-with)
Two minor releases of vulnerability DB/scanner logic. exit-code: '0' means it won't fail the job, but the SARIF results could surface new/different findings in the Security tab worth a glance after merge.

3. jdx/mise-action v4.0.1 → v4.2.0 (gitleaks.yaml)
v4.1.0 introduces auto --locked install when a mise.lock file exists — checked, this repo has no mise.lock (gitleaks version is pinned inline via mise_toml), so no impact. Also brings a cache-key change (now includes runner image) — expect one harmless cache miss on first run post-merge.

4. actions/stale v10.2.0 → v10.3.0 (stale-prs.yaml)
Behavior tweak: "ignore stale labeling events" — minor, shouldn't change your config's intent but worth knowing the bot's exact staleness logic shifted slightly.

5. astral-sh/setup-uv v8.1.0 → v8.3.2 (.github/actions/setup-uv/action.yml)
v8.3.0 added "support uv.lock as a version-file source" — but this action uses version-file: pyproject.toml, not uv.lock, so that new behavior doesn't engage. No impact.

6. CodeRabbit's own PR checks (informational, not from our fix):

  • ⚠️ "Description check" — Renovate's templated body doesn't fill this repo's PR template (Description/How Tested/checklist). Cosmetic for an automated PR; not merge-blocking based on the "9 passed / 1 warning / 1 inconclusive" summary.
  • ❓ "Title check" — suggests a more specific title than "Update github-actions". Cosmetic only.
  • Its own tool sub-runs (actionlint/zizmor/checkov) errored trying to read .github/workflows/semgrep.yaml — that file exists and is touched by this diff, so this looks like a CodeRabbit-side tooling glitch, not a real repo issue.
  • Supply-chain reminder from CodeRabbit: verify each new SHA resolves to its claimed tag before merging — standard Renovate-PR due diligence, already implicitly covered since Renovate does the SHA resolution itself, but worth a spot-check if you're paranoid.

7. Approval gate: openshift-ci shows "NOT APPROVED" — needs an OWNERS approval (you're the fallback approver per the bot message) plus review from atheo89/ayush17 before merge, as usual.

Nothing here contradicts or threatens the RHAIENG-6163 fix — the grouped PR is exactly what we expected to unblock. Only trivy and codeql-action bundle-version are worth a post-merge glance; everything else is routine.

@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown
Contributor

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "=== Checking SHA-pinning discipline for bumped actions ==="
rg -n 'uses:\s*(github/codeql-action|docker/login-action|docker/setup-buildx-action|docker/build-push-action|actions/stale|actions/cache|actions/setup-go|actions/setup-python|jdx/mise-action|golangci/golangci-lint-action|snok/container-retention-policy|pnpm/action-setup|astral-sh/setup-uv|aquasecurity/trivy)' .github/workflows/*.yaml .github/workflows/*.yml .github/actions/setup-uv/action.yml 2>/dev/null | grep -v '@[0-9a-f]\{40\}' || echo "ALL PINNED: no non-SHA uses lines found"

echo
echo "=== golangci-lint version value in code-quality.yaml ==="
rg -n -B2 -A2 'golangci-lint-action|version:' .github/workflows/code-quality.yaml

echo
echo "=== mise.lock presence check ==="
fd -H 'mise.lock' . || echo "no mise.lock found"

echo
echo "=== setup-uv action.yml version-file input ==="
cat .github/actions/setup-uv/action.yml

Length of output: 2444


Verified.

SHA-pinning: confirmed 100% — every uses: line for the bumped actions resolves to a full 40-char commit SHA, no mutable tags. This is the correct mitigation against tag-hijack attacks (CWE-829, Inclusion of Functionality from Untrusted Control Sphere) — the class of attack behind CVE-2026-33634 (Trivy tag force-push compromise). No exposure via that vector here.

golangci-lint-action: confirmed — version: v2.12.2 in .github/workflows/code-quality.yaml:127 unchanged, only the action wrapper SHA moved (v9.3.0). RHAIENG-6163 fix intact.

mise.lock: confirmed absent from the repo, so your point 3 (--locked auto-install in mise-action v4.1.0+) is correctly assessed as no-impact.

setup-uv: confirmed — version-file: pyproject.toml in .github/actions/setup-uv/action.yml:11, not uv.lock. Your point 5 holds; the v8.3.0 uv.lock-as-version-source behavior doesn't engage.

One correction on your codeql-action note: v4.36.0's bundle-version bump to 2.19.4 is enforced by the action at runtime, not by anything in this repo's config — there's no pinned bundle version to check against, so it's a pure runtime risk, not a config-verifiable one. If any of codeql.yaml, gitleaks.yaml, semgrep.yaml, or security.yaml CodeQL/init jobs fail post-merge with a bundle compatibility error, that's the action enforcing a floor you can't preempt from the workflow files — only fixable by a further action bump or explicit tools: pin.

No other findings beyond what's already listed. Nothing here weakens the sha-pinning control or reopens RHAIENG-6163.

(=^ェ^=)

@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown
Contributor

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
rg -n 'golangci-lint-action|version:' .github/workflows/code-quality.yaml -A2 -B2

Length of output: 512


🤖 web_search executed:

github/codeql-action v4.36.0 changelog minimum CodeQL bundle version 2.19.4 breaking change

Length of output: 3925


@jiridanek Verified both flagged points against the repo and upstream changelog:

golangci-lint-action / version: v2.12.2 — confirmed unchanged at Line 127 of .github/workflows/code-quality.yaml:

125: uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a  # v9.3.0
127:   version: v2.12.2

RHAIENG-6163 mitigation holds — no digest-pin regression on that input.

codeql-action v4.36.0 bundle-version breaking change — confirmed from upstream CHANGELOG.md: "Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4" (github/codeql-action#3894), with default bundle raised to 2.26.0 by the time you land on v4.37.0. Only exploitable failure mode: a self-hosted runner with a CodeQL CLI pinned below 2.19.4. GitHub-hosted runners ship current bundles, so codeql.yaml, gitleaks.yaml, semgrep.yaml, and security.yaml — none of which set tools:/pin a bundle — are unaffected here. No action needed unless a self-hosted runner is introduced later.

No new CVE/CWE surface beyond what's already been called out (CVE-2026-33634 Trivy tag-hijack — irrelevant here due to SHA-pinning; CWE-829 CodeQL config-file remote-fetch — not enabled). Your assessment stands: routine bump, RHAIENG-6163 fix intact, blocking item remains the OWNERS approval gate.

@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown
Contributor

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
echo "--- code-quality.yaml golangci section ---"
rg -n "golangci|version:" .github/workflows/code-quality.yaml -A2 -B2
echo "--- semgrep.yaml exists ---"
fd -t f semgrep.yaml .github/workflows
echo "--- mise.lock search ---"
fd -H "mise.lock" .
echo "--- gitleaks.yaml mise config ---"
cat .github/workflows/gitleaks.yaml | rg -n "mise" -A3 -B3

Length of output: 1533


🤖 web_search executed:

github/codeql-action v4.36.0 changelog release notes minimum CodeQL bundle version 2.19.4

Length of output: 2783


🤖 web_search executed:

jdx/mise-action v4.1.0 changelog release notes --locked mise.lock cache key

Length of output: 12525


@jiridanek Verified against source.

Confirmed correct:

  • code-quality.yaml line 127: version: v2.12.2 unchanged under golangci/golangci-lint-action@...# v9.3.0 (line 125). RHAIENG-6163 pin discipline holds — Renovate touched only the uses: SHA/comment, not the with.version value.
  • No mise.lock in this repo (confirmed empty fd result) — jdx/mise-action v4.1.0's new auto --locked behavior (PR feat: lock install when mise.lock is present jdx/mise-action#495) does not engage. Confirmed.
  • github/codeql-action v4.36.0 changelog explicitly states: "Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4" (jdx/mise-action... correction, Bump minimum CodeQL CLI version to 2.19.4 github/codeql-action#3894), with default bundle now 2.26.0. None of codeql.yaml/gitleaks.yaml/semgrep.yaml/security.yaml pin an explicit bundle, so this is transparent as you said — but flag it as CWE-1104 (use of unmaintained third-party components) risk class if anyone ever hardcodes an old bundle version here later.
  • jdx/mise-action v4.1.0 also changed the cache key to include runner image ({{platform}} now appends OS image or self-hosted) — confirmed via changelog. One cache miss expected post-merge on gitleaks.yaml, as you noted.

One correction to your writeup: the mise-action bump is v4.0.1 → v4.2.0, not "v4.0.1 → v4.1.0" alone — v4.1.0 introduced the --locked + cache-key changes you described, and v4.2.0 layers on top (Windows shim fix, wings_enabled input). Doesn't change your no-impact conclusion, just noting the full delta for the record.

Remaining unverified item: your claim that Renovate's own SHA resolution covers the "verify each SHA resolves to its claimed tag" due diligence. That's true for the resolution step, but it does not protect against a tag being force-pushed after Renovate opened the PR and before merge — a live TOCTOU gap for SHA-pin renovation (relevant given the CVE-2026-33634 tag-hijack precedent I cited earlier). Worth a final git ls-remote spot-check on the pinned SHAs immediately before merge if this PR sits open for more than a day.

No open objections to your assessment. Approval gate (item 7) is outside my visibility — that's on OWNERS review.

[resolve]


✏️ Learnings added
Learnt from: jiridanek
URL: https://github.com/opendatahub-io/notebooks/pull/4032

Timestamp: 2026-07-09T14:00:07.950Z
Learning: In opendatahub-io/notebooks, `.github/workflows/code-quality.yaml` intentionally pins `golangci/golangci-lint-action` by SHA (version comment updated by Renovate) while keeping the `with.version` input (golangci-lint's own release, e.g. v2.12.2) manually controlled and unchanged — this separation is required per RHAIENG-6163 to prevent Renovate from also bumping the linter's own version via the action's `version` input. When reviewing Renovate PRs touching this file, confirm `with.version` stays untouched.

Note: Learnings are effective only in the context of similar code segments. To apply general coding guidelines, please configure review instructions. You can manage existing learnings in the app.

@openshift-ci

openshift-ci Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: jiridanek

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved label Jul 9, 2026
@jiridanek
jiridanek merged commit 0f319a0 into main Jul 9, 2026
47 checks passed
@jiridanek
jiridanek deleted the konflux/mintmaker/main/github-actions branch July 9, 2026 14:01
@coderabbitai

coderabbitai Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

An error occurred during the review process. Please try again later.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch konflux/mintmaker/main/github-actions

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved lgtm review-requested GitHub Bot creates notification on #pr-review-ai-ide-team slack channel size/m

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants