Repository navigation
Conversation
1ee9fac to
0a03165
Compare
The devops-actions/actionlint wrapper runs an old rhysd/actionlint release. Use the maintained kjanat/actionlint fork's own action instead, pinned to the commit that pins its image by digest. Since v1.17.0 knows about the ubuntu-26.04 runner label, the self-hosted-runner escape hatch in .github/actionlint.yaml is no longer needed, so drop it. Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
0a03165 to
273083b
Compare
| with: | ||
| persist-credentials: false | ||
| - uses: devops-actions/actionlint@ec02b36684b2f574f1d219ad0a43b082e46bf3e4 # v0.1.13 | ||
| - uses: kjanat/actionlint@722799fa4b8cc6734debb97bae24aca9e0dbaf59 # v1.17 |
There was a problem hiding this comment.
Perhaps this should use v1.17.0 (instead of v1.17, which may be a rolling tag?)
There was a problem hiding this comment.
In fact it's better to use v1.17 here. The v1.17 tag points to the commit right after the release (722799f, "pin the action image of v1.17.0 to its digest"), which pins the image by digest. That is what the upstream README recommends ("For an immutable action reference with a pinned image, use the full commit SHA resolved from a floating tag").
Since we pin by SHA anyway, the rolling nature of v1.17 doesn't matter here — the comment just says which tag the SHA was resolved from.
There was a problem hiding this comment.
technically, for the immutable tags, we wouldn't even need to pin to a sha (they can't be updated, unless github itself is compromised)
There was a problem hiding this comment.
See, the issue here is, if we use v1.17.0 (or its sha, doesn't matter), the docker image used by the action is not pinned to a sha (which is what kjanat/actionlint@722799f fixes).
Which is understandable: the author sets a tag, builds a docker image, uploads it and only after that they can pin docker image to a sha. Chicken-and-egg problem here and the solution is rolling tag (which we pin to a sha so it's not a problem).
If you're OK with using unpinned docker image from an action, AND zizmor knows about immutable tags and thus won't complan about v1.17.0, I'm happy to change the above to
- uses: kjanat/actionlint@v1.17.0There was a problem hiding this comment.
wait, but does the action run an image, or the action itself?
There was a problem hiding this comment.
oh! the action is just a wrapper for an image that runs the actual work 🤔
There was a problem hiding this comment.
So now when we figured this out they've moved away from docker image (in kjanat/actionlint#185) so for the next version (1.18 or 2.0, I dunno) we will need a specific non-floating tag (and if the tag is immutable, we can drop sha, hope zizmor knows about immutable tags).
So this can be merged as is for now and I'm not adding a comment about v1.17.0 vs v1.17.

The
devops-actions/actionlintwrapper runs an oldrhysd/actionlintrelease. Use the maintained
kjanat/actionlintfork's own action instead,pinned to the commit that pins its container image by digest (as
recommended by its README; the release tag itself references the image
by a floating tag).
Since v1.17.0 knows about the
ubuntu-26.04runner label, theself-hosted-runnerescape hatch in.github/actionlint.yamlis nolonger needed, so drop it.
Checked locally with the v1.17.0 binary (the same one the action's
container runs), without
.github/actionlint.yaml: no findings.