Skip to content

⚙️ [Maintenance]: Workflow reference pinned to immutable SHA - #575

Merged
Marius Storhaug (MariusStorhaug) merged 1 commit into
mainfrom
fix/574-pin-process-psmodule-sha
Apr 4, 2026
Merged

⚙️ [Maintenance]: Workflow reference pinned to immutable SHA#575
Marius Storhaug (MariusStorhaug) merged 1 commit into
mainfrom
fix/574-pin-process-psmodule-sha

Conversation

@MariusStorhaug

Copy link
Copy Markdown
Member

The CI workflow reference is now pinned to a specific commit SHA, consistent with all other uses: references in the PSModule infrastructure. Dependabot will automatically propose updates when new versions of Process-PSModule are released.

Changed: Workflow reference pinned to immutable SHA

The Process-PSModule reusable workflow reference in .github/workflows/Process-PSModule.yml was using a mutable major version tag (@v5). It is now pinned to the exact commit SHA with the patch-level version in a trailing comment:

# Beforeuses: PSModule/Process-PSModule/.github/workflows/workflow.yml@v5# Afteruses: PSModule/Process-PSModule/.github/workflows/workflow.yml@4343d76f9e8c9468527175ea292092c2d055be8c # v5.4.5

Dependabot's github-actions ecosystem is already configured and will keep this reference up to date automatically.

Technical Details

  • Changed @v5 to @4343d76f9e8c9468527175ea292092c2d055be8c # v5.4.5 in .github/workflows/Process-PSModule.yml.
  • The existing dependabot.yml already covers github-actions in /, so SHA-pinned reusable workflow references will be updated automatically.
  • No functional change — v5 currently resolves to the same commit (4343d76).

@github-actions

Copy link
Copy Markdown
Contributor

No Significant Changes Detected

This PR does not contain changes to files that would trigger a new release:

PathDescription
src/**Module source code
README.mdDocumentation

Build, test, and publish stages will be skipped for this PR.

If you believe this is incorrect, please verify that your changes are in the correct locations.

@MariusStorhaug
Marius Storhaug (MariusStorhaug) marked this pull request as ready for review April 4, 2026 23:02
CopilotAI review requested due to automatic review settings April 4, 2026 23:02

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins the repository’s Process-PSModule reusable workflow reference to an immutable commit SHA to align with the existing security hardening pattern for GitHub Actions uses: references and enable safe Dependabot updates.

Changes:

  • Updated .github/workflows/Process-PSModule.yml to replace the mutable @v5 tag with a full commit SHA.
  • Added a trailing comment to preserve the human-readable patch version (# v5.4.5).

@MariusStorhaug
Marius Storhaug (MariusStorhaug) merged commit 33bc295 into mainApr 4, 2026
45 of 46 checks passed
@MariusStorhaug
Marius Storhaug (MariusStorhaug) deleted the fix/574-pin-process-psmodule-sha branch April 4, 2026 23:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

Pin Process-PSModule workflow reference to SHA with patch-level version comment

2 participants

@MariusStorhaug