Skip to content

ci: bump and pin third-party actions to commit SHAs - #188

Draft
GuillaumeLagrange wants to merge 2 commits into
mainfrom
chore/pin-github-actions
Draft

ci: bump and pin third-party actions to commit SHAs#188
GuillaumeLagrange wants to merge 2 commits into
mainfrom
chore/pin-github-actions

Conversation

@GuillaumeLagrange

Copy link
Copy Markdown
Contributor

Every uses: reference is now pinned to a full commit SHA with a version comment, managed by pinact (.pinact.yaml). This removes the mutable-tag supply-chain risk and clears the Node 20 deprecation warning, which came from actions/checkout@v4, not from CodSpeedHQ/action.

CodSpeedHQ/action@main is deliberately left unpinned so CI keeps exercising the action's unreleased changes; pinact ignores it.

Replace actions/upload-release-asset@v1.0.2 with gh release upload: that action is archived and still targets Node 12, which current runners no longer execute. The release tag now flows from the publish job as a tag output instead of the upload_url output it replaces.

Every `uses:` reference is now pinned to a full commit SHA with a version
comment, managed by pinact (`.pinact.yaml`). This removes the mutable-tag
supply-chain risk and clears the Node 20 deprecation warning, which came
from `actions/checkout@v4`, not from CodSpeedHQ/action.

`CodSpeedHQ/action@main` is deliberately left unpinned so CI keeps
exercising the action's unreleased changes; pinact ignores it.

Replace `actions/upload-release-asset@v1.0.2` with `gh release upload`:
that action is archived and still targets Node 12, which current runners
no longer execute. The release tag now flows from the `publish` job as a
`tag` output instead of the `upload_url` output it replaces.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Guillaume Lagrange <guillaume@glagrange.eu>
@GuillaumeLagrange
GuillaumeLagrange force-pushed the chore/pin-github-actions branch from b4c5d5f to dccdc66 Compare August 18, 2026 13:42
@codspeed-hq

codspeed-hq Bot commented Aug 18, 2026

Copy link
Copy Markdown

Hooray! CodSpeed harness just leveled up!

The base and head of this comparison were measured with different runner settings, so their benchmark values are not directly comparable.

What changed between base and head:

Re-run the base with the same settings to get a valid performance comparison.


Comparing chore/pin-github-actions (1d05f61) with main (69f74b6)

Open in CodSpeed

@codspeed-hq

codspeed-hq Bot commented Aug 18, 2026

Copy link
Copy Markdown

Unable to generate the flame graphs

The performance report has correctly been generated, but there was an internal error while generating the flame graphs for this run. We're working on fixing the issue. Feel free to contact us on Discord or at support@codspeed.io if the issue persists.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant