Lesson 18 / 25
Pinning Third-Party Actions
Tags can move; commit SHAs cannot.
Supply-chain risk of mutable tags
Referencing some/action@v3 trusts whatever commit the tag points to now and in the future; if the action's repository is compromised, the tag can be moved to malicious code, as has happened in real incidents. Pin third-party actions to a full commit SHA (with the version in a comment), review updates with Dependabot or Renovate, prefer actions from verified creators, and restrict which actions are allowed at the organisation level. First-party actions/* are lower risk but can be pinned too.
Tag versus SHA pinning
The SHA shown is a placeholder; use the real commit of the version you reviewed. Not run here.
# mutable: the tag can be moved to different code later
- uses: some-org/deploy-action@v3
# immutable: this exact commit, version noted for humans and Dependabot
- uses: some-org/deploy-action@0123456789abcdef0123456789abcdef01234567 # v3.2.1Let Dependabot update pinned SHAs
Dependabot understands SHA pins with version comments and opens pull requests when new versions are released.
Quick check: Why pin actions to a commit SHA instead of a tag?
- Tags can be moved to different code; a SHA always refers to the same code
- SHAs run faster
- Tags are not allowed
- SHAs include secrets
Answer
Tags can be moved to different code; a SHA always refers to the same code — Immutable references.