Repository navigation
ci: pin upload-sarif to the release commit rather than its tag object - #15
Merged
Merged
Conversation
The upload-sarif step was pinned to c23de5a8, the annotated tag object for v4.38.1, rather than to the commit the tag points to. GitHub Actions resolves either, so the workflow kept passing. Scorecard's publishing API does not accept it: it rejected every run on main since the pin was set with "imposter commit: c23de5a8... does not belong to github/codeql-action/upload-sarif". The action reports that as a warning, so the job stayed green while the published results stopped updating. The upload to code scanning was not affected. Pin 1c5b6756, the commit that v4.38.1 and v4 point to. The version and the code that runs are unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pins
github/codeql-action/upload-sarifin the Scorecard workflow to the commit that v4.38.1 points to, rather than to the tag object.Why
The pinned SHA,
c23de5a82f64bb08c6d9f28844551440ca298e76, is the annotated tag object for v4.38.1, not a commit. GitHub Actions resolves it, so the workflow has kept passing. Scorecard's publishing API does not accept it. Every run onmainsince the pin was set has logged:The action reports the rejection as a warning, so the job stayed green while the results published for this repository stopped updating. The upload to code scanning was not affected.
Change
One line in
.github/workflows/scorecard.yml. The tag object points to1c5b675653bb5c22dbe9b12b556ec555138e09fd, which carries thev4.38.1andv4tags, so the version and the code that runs are unchanged. The trailing comment still reads# v4.38.1.Verification
repos/github/codeql-action/git/tags/c23de5a8…resolves toobject.type: commit,object.sha: 1c5b6756…, and the repository's tag list putsv4.38.1andv4on that commit.mainlogged no verification error, and the published result moved to that commit.🤖 Generated with Claude Code