Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 0 additions & 5 deletions .github/actionlint.yaml

This file was deleted.

2 changes: 1 addition & 1 deletion .github/workflows/actionlint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,4 +23,4 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: devops-actions/actionlint@ec02b36684b2f574f1d219ad0a43b082e46bf3e4 # v0.1.13
- uses: kjanat/actionlint@722799fa4b8cc6734debb97bae24aca9e0dbaf59 # v1.17

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps this should use v1.17.0 (instead of v1.17, which may be a rolling tag?)

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In fact it's better to use v1.17 here. The v1.17 tag points to the commit right after the release (722799f, "pin the action image of v1.17.0 to its digest"), which pins the image by digest. That is what the upstream README recommends ("For an immutable action reference with a pinned image, use the full commit SHA resolved from a floating tag").

Since we pin by SHA anyway, the rolling nature of v1.17 doesn't matter here — the comment just says which tag the SHA was resolved from.

@thaJeztah thaJeztah Oct 7, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right, but v1.17.0 is an immutable tag, and signed.

If the floating v1.17 tag is updated, there's no way to verify if the commit we picked was ever matching that release.

IMG_2840

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

technically, for the immutable tags, we wouldn't even need to pin to a sha (they can't be updated, unless github itself is compromised)

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See, the issue here is, if we use v1.17.0 (or its sha, doesn't matter), the docker image used by the action is not pinned to a sha (which is what kjanat/actionlint@722799f fixes).

Which is understandable: the author sets a tag, builds a docker image, uploads it and only after that they can pin docker image to a sha. Chicken-and-egg problem here and the solution is rolling tag (which we pin to a sha so it's not a problem).

If you're OK with using unpinned docker image from an action, AND zizmor knows about immutable tags and thus won't complan about v1.17.0, I'm happy to change the above to

- uses: kjanat/actionlint@v1.17.0

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wait, but does the action run an image, or the action itself?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

oh! the action is just a wrapper for an image that runs the actual work 🤔

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So now when we figured this out they've moved away from docker image (in kjanat/actionlint#185) so for the next version (1.18 or 2.0, I dunno) we will need a specific non-floating tag (and if the tag is immutable, we can drop sha, hope zizmor knows about immutable tags).

So this can be merged as is for now and I'm not adding a comment about v1.17.0 vs v1.17.

Loading