Skip to content

DEVOPS-1133: Pin GitHub Actions to commit hashes - #456

Open
RomFloreani wants to merge 5 commits into
developfrom
DEVOPS-1133
Open

DEVOPS-1133: Pin GitHub Actions to commit hashes#456
RomFloreani wants to merge 5 commits into
developfrom
DEVOPS-1133

Conversation

@RomFloreani

@RomFloreani RomFloreani commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

DEVOPS-1133 - pin all GitHub actions and reusable workflows to hash
Expands moving GitHub Actions tags to the full semver tag pointing at the same commit, then pins every uses: to a commit hash with a dependabot-readable version comment.

Tags expanded in this repo:

  • MiraGeoscience/CI-tools/.github/workflows/reusable-jira-issue_to_jira.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-jira-pr_actions.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-static_analysis.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-pytest.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_rattler_package.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_pypi_package.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_conda_assets.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_pypi_assets.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-advanced-security.yml@v3 -> @v3.9.1
  • MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-annotate.yml@v3 -> @v3.9.1

Copilot AI review requested due to automatic review settings July 29, 2026 16:41
@github-actions github-actions Bot changed the title Pin GitHub Actions to commit hashes DEVOPS-1133: Pin GitHub Actions to commit hashes Jul 29, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates this repository’s GitHub Actions reusable-workflow references to use the MiraGeoscience/CI-tools v3.9.1 tag instead of the floating v3 major tag across all workflows.

Changes:

  • Updated all uses: MiraGeoscience/CI-tools/...@v3 references to @v3.9.1.
  • Applied the same version bump consistently across security scan, Python analysis/deploy, and JIRA automation workflows.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 6 comments.

Show a summary per file
File Description
.github/workflows/security_scan.yml Updates Zizmor reusable workflow references from v3 to v3.9.1.
.github/workflows/python_deploy_prod.yml Updates Conda/PyPI production release reusable workflow references from v3 to v3.9.1.
.github/workflows/python_deploy_dev.yml Updates Conda/PyPI development publish reusable workflow references from v3 to v3.9.1.
.github/workflows/python_analysis.yml Updates static analysis and pytest reusable workflow references from v3 to v3.9.1.
.github/workflows/pr_jira_actions.yml Updates PR→JIRA reusable workflow reference from v3 to v3.9.1.
.github/workflows/issue_to_jira.yml Updates issue→JIRA reusable workflow reference from v3 to v3.9.1.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/security_scan.yml Outdated
contents: read
actions: read
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-advanced-security.yml@v3
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-advanced-security.yml@v3.9.1
name: Publish production Conda package on JFrog Artifactory
if: ${{ github.event_name == 'release' || github.event.inputs.publish-conda == 'true' }}
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_conda_assets.yml@v3
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_conda_assets.yml@v3.9.1
Comment thread .github/workflows/python_deploy_dev.yml Outdated
call-workflow-conda-publish:
name: Publish development conda package on JFrog Artifactory
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_rattler_package.yml@v3
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_rattler_package.yml@v3.9.1
Comment thread .github/workflows/python_analysis.yml Outdated
call-workflow-static-analysis:
name: Static analysis
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-static_analysis.yml@v3
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-static_analysis.yml@v3.9.1
Comment thread .github/workflows/pr_jira_actions.yml Outdated
jobs:
call-workflow-pr_jira_actions:
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-jira-pr_actions.yml@v3
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-jira-pr_actions.yml@v3.9.1
Comment thread .github/workflows/issue_to_jira.yml Outdated
jobs:
call-workflow-create-jira-issue:
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-jira-issue_to_jira.yml@v3
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-jira-issue_to_jira.yml@v3.9.1
@codecov

codecov Bot commented Aug 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.29%. Comparing base (295f324) to head (4aabc15).
⚠️ Report is 9 commits behind head on develop.

Additional details and impacted files
@@             Coverage Diff             @@
##           develop     #456      +/-   ##
===========================================
+ Coverage    90.27%   90.29%   +0.02%     
===========================================
  Files          113      113              
  Lines         7020     7020              
  Branches       865      865              
===========================================
+ Hits          6337     6339       +2     
+ Misses         466      465       -1     
+ Partials       217      216       -1     

see 1 file with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants