Skip to content

ci: pin claude-code-action to a SHA in claude-code-review.yml - #112

Merged
jnasbyupgrade merged 1 commit into
Postgres-Extensions:masterfrom
jnasbyupgrade:pin-action-shas
Sep 8, 2026
Merged

ci: pin claude-code-action to a SHA in claude-code-review.yml#112
jnasbyupgrade merged 1 commit into
Postgres-Extensions:masterfrom
jnasbyupgrade:pin-action-shas

Conversation

@jnasbyupgrade

@jnasbyupgrade jnasbyupgrade commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Summary

  • claude-code-review.yml's job runs as pull_request_target with pull-requests: write, so a moved upstream tag must not silently change what code runs -- the same reasoning already applied to github-script's SHA pin in ci.yml/protect-label.yml (see those comments). claude-code-action was the one action in this trust class still tracking a mutable tag (@v1) instead of a SHA.
  • actions/checkout (here and elsewhere) and claude.yml's own claude-code-action@v1 stay on tags deliberately -- existing comments already explain why ("so upstream fixes are picked up automatically"); checkout only reads the base branch, and claude.yml runs under a narrower trust boundary (actor-gated, read-only permissions), not pull_request_target with write access. This PR doesn't touch either.

Companion pgxntool-test PR: Postgres-Extensions/pgxntool-test#80

This job runs as pull_request_target with pull-requests: write, so a moved
upstream tag must not silently change what code runs -- the same reasoning
already applied to github-script's pin in ci.yml/protect-label.yml (see
those comments). claude-code-action was the one action in this trust class
still tracking a mutable tag (@v1) instead of a SHA.

`actions/checkout` and claude.yml's own claude-code-action@v1 stay on tags
deliberately (existing comments: "so upstream fixes are picked up
automatically") -- checkout only reads the base branch, and claude.yml runs
under a much narrower trust boundary (actor-gated, read-only permissions),
not pull_request_target with write access. This change doesn't touch either.

Related changes in pgxntool-test:
- Same fix, same rationale, mirrored in its own claude-code-review.yml

Co-Authored-By: Claude <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 6ed3e8fb-e07b-472b-b581-5a90d4b4f395

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

@jnasbyupgrade
jnasbyupgrade merged commit 5aafc8f into Postgres-Extensions:master Sep 8, 2026
5 checks passed
@jnasbyupgrade
jnasbyupgrade deleted the pin-action-shas branch September 8, 2026 20:42
jnasbyupgrade added a commit to Postgres-Extensions/pgxntool-test that referenced this pull request Sep 8, 2026
Related pgxntool PR:
Postgres-Extensions/pgxntool#112

## Summary
- Same fix, same rationale as the pgxntool PR above: this job runs as
`pull_request_target` with `pull-requests: write`, so a moved upstream
tag must not silently change what code runs -- matching the SHA pin
already used for `github-script` in pgxntool's
`ci.yml`/`protect-label.yml`. `claude-code-action` was the one action in
this trust class still tracking a mutable tag (`@v1`).
- `actions/checkout` here and `claude.yml`'s own `claude-code-action@v1`
stay on tags deliberately (existing comments explain why); this PR
doesn't touch either.

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant