पाठ 18 / 25

Pinning Third-Party Actions

Tags can move; commit SHAs cannot.

Supply-chain risk of mutable tags

Referencing some/action@v3 trusts whatever commit the tag points to now and in the future; if the action's repository is compromised, the tag can be moved to malicious code, as has happened in real incidents. Pin third-party actions to a full commit SHA (with the version in a comment), review updates with Dependabot or Renovate, prefer actions from verified creators, and restrict which actions are allowed at the organisation level. First-party actions/* are lower risk but can be pinned too.

Tag versus SHA pinning

The SHA shown is a placeholder; use the real commit of the version you reviewed. Not run here.

# mutable: the tag can be moved to different code later
- uses: some-org/deploy-action@v3

# immutable: this exact commit, version noted for humans and Dependabot
- uses: some-org/deploy-action@0123456789abcdef0123456789abcdef01234567  # v3.2.1

Let Dependabot update pinned SHAs

Dependabot understands SHA pins with version comments and opens pull requests when new versions are released.

त्वरित जाँच: Why pin actions to a commit SHA instead of a tag?

  • Tags can be moved to different code; a SHA always refers to the same code
  • SHAs run faster
  • Tags are not allowed
  • SHAs include secrets
Answer

Tags can be moved to different code; a SHA always refers to the same code — Immutable references.