Uh oh!
There was an error while loading. Please reload this page.
fix: pin secure-action-inputs to v1.0.0 SHA instead of floating @main - #323
Merged
Conversation
Now that secure-action-inputs has a tagged v1.0.0 release, pin the reusable workflow's action reference by commit SHA (with version comment) so Dependabot can track and bump it, matching the pattern already used for step-security/harden-runner in this same file. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
Dependency ReviewThe following issues were found:
Snapshot WarningsEnsure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice. License Issues.github/workflows/secure-inputs.yml
OpenSSF Scorecard
Scanned Files
|
Uh oh!
There was an error while loading. Please reload this page.
This was referenced Jul 1, 2026
Merged
Merged
rajbos added a commit
to devops-actions/action-template
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/actionlint
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/actionlint-testing-repo
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/alternative-github-actions-marketplace
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/azure-appservice-settings
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/azure-devops-extension-news
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/demo-actions
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/github-actions-marketplace-news
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/github-copilot-memories
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/github-user-stats
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/issue-comment-tag
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/load-dependents-count
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/load-runner-info
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/secure-action-inputs
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/load-used-actions
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rajbos added a commit
to devops-actions/load-available-actions
that referenced
this pull request
Jul 1, 2026
* chore: bump secure-inputs reusable workflow pin Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * chore: update version comment to v1.1.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
gh-github-automationBot
pushed a commit
to actions-marketplace-validations/devops-actions_json-to-file
that referenced
this pull request
Jul 30, 2026
Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
gh-github-automationBot
pushed a commit
to actions-marketplace-validations/devops-actions_github-copilot-pr-analysis
that referenced
this pull request
Aug 5, 2026
Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable workflow to latest main, which now pins secure-action-inputs to a tagged v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Now that
devops-actions/secure-action-inputshas a taggedv1.0.0release, this pins the reusable workflow's action reference by commit SHA (with version comment) instead of the floating@mainbranch ref.Why: Dependabot's
github_actionsupdate checker requires at least one git tag on the referenced repo before it will compute a new commit SHA for updates (seelatest_commit_shain dependabot-core, which returns early whenlatest_version_tagis nil). A floating@mainref is also never tracked by Dependabot at all — it only updates SHA or tag pins.Related:
devops-actions/.githubanddevops-actions/secure-action-inputsboth previously had zero tags, which is also why Dependabot never proposed updates to consumers' SHA-pinneduses: devops-actions/.github/.github/workflows/secure-inputs.yml@<sha> # mainreferences. Both repos now have av1.0.0tag/release to unblock that.