Skip to content

DEV: pin github actions to hashes - #69

Merged
GavinHuttley merged 1 commit into
HuttleyLab:developfrom
GavinHuttley:develop
Jul 23, 2026
Merged

DEV: pin github actions to hashes#69
GavinHuttley merged 1 commit into
HuttleyLab:developfrom
GavinHuttley:develop

Conversation

@GavinHuttley

@GavinHuttley GavinHuttley commented Jul 23, 2026

Copy link
Copy Markdown
Collaborator

Summary by Sourcery

Pin GitHub Actions used in CI and release workflows to specific commit SHAs for improved reproducibility and security.

Build:

  • Update workflow references for checkout, setup-uv, setup-python, upload-artifact, and download-artifact to pinned commit hashes rather than version tags.

CI:

  • Adjust testing workflow to use pinned Coveralls GitHub Action SHA and add a macOS-specific step to trust the Coveralls Homebrew tap before running coverage reporting.

@sourcery-ai

sourcery-ai Bot commented Jul 23, 2026

Copy link
Copy Markdown

Reviewer's Guide

Pins all GitHub Actions used in testing and release workflows to specific commit hashes, updates some action versions, and adjusts Coveralls usage and macOS tap trust handling.

Flow diagram for updated testing_develop GitHub Actions workflow

flowchart TD
    A[testing_develop job start] --> B["actions_checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0"]
    B --> C["astral_sh_setup_uv@11f9893b081a58869d3b5fccaea48c9e9e46f990"]
    C --> D["actions_setup_python@ece7cb06caefa5fff74198d8649806c4678c61a1"]
    D --> E[nox test matrix]
    E --> F{runner.os == macOS?}
    F -->|yes| G["brew trust coverallsapp/coveralls"]
    F -->|no| H[skip tap trust]
    G --> I["coverallsapp_github_action@5cbfd81b66ca5d10c19b062c04de0199c215fb6e"]
    H --> I
    I --> J["Coveralls Finished job using coverallsapp_github_action@5cbfd81b66ca5d10c19b062c04de0199c215fb6e"]
Loading

File-Level Changes

Change Details Files
Pin GitHub Actions in testing workflow to specific commit SHAs and adjust Coveralls/macOS handling.
  • Replace version tags for actions/checkout, astral-sh/setup-uv, actions/setup-python with corresponding commit hashes while documenting the original versions in comments.
  • Update actions/setup-python from v6.2.0 to v6.3.0 when pinning by hash.
  • Introduce a separate macOS-only step to trust the Coveralls Homebrew tap instead of relying on HOMEBREW_NO_REQUIRE_TAP_TRUST env var.
  • Pin coverallsapp/github-action to a specific commit hash and remove the HOMEBREW_NO_REQUIRE_TAP_TRUST environment variable.
.github/workflows/testing_develop.yml
Pin GitHub Actions in release workflow to specific commit SHAs and update artifact actions.
  • Replace version tags for actions/checkout, astral-sh/setup-uv, actions/setup-python with corresponding commit hashes while documenting the original versions in comments, including setup-python v6.3.0.
  • Pin actions/upload-artifact to a specific commit hash corresponding to v7.0.1.
  • Pin actions/download-artifact to a specific commit hash corresponding to v8.0.1.
.github/workflows/release.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • The actions/setup-python pin updates from v6.2.0 to a digest commented as v6.3.0; if the intention was only to pin, consider either keeping the original version or explicitly calling out the upgrade in the PR title/description.
  • The new brew trust coverallsapp/coveralls step introduces a dependency on Homebrew’s tap trust semantics; it may be worth adding a brief inline comment explaining why this is needed to avoid confusion for future maintainers.
Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- The `actions/setup-python` pin updates from v6.2.0 to a digest commented as v6.3.0; if the intention was only to pin, consider either keeping the original version or explicitly calling out the upgrade in the PR title/description.
- The new `brew trust coverallsapp/coveralls` step introduces a dependency on Homebrew’s tap trust semantics; it may be worth adding a brief inline comment explaining why this is needed to avoid confusion for future maintainers.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@GavinHuttley
GavinHuttley merged commit 08c8695 into HuttleyLab:develop Jul 23, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant