Skip to content

The pnpm/action-setup pin in the check template is a tag object SHA, not a commit #7

Description

@lemarier

templates/workflows/origin89-check.yml pins pnpm/action-setup@f520eceda224fe1a4aed5a2a27a194379a409996 # v6. That SHA is the annotated tag object for v6, not a commit: git ls-remote --tags https://github.com/pnpm/action-setup lists f520ece… refs/tags/v6 and 0977fd9… refs/tags/v6^{}, and GET /repos/pnpm/action-setup/commits/f520ece… answers 422 No commit found for SHA.

Expected: a uses: pin that Actions can resolve, which is the full commit SHA. Actual: a job using this template step cannot start the action once it reaches it. It has not been observed in a run yet because the first consumer, origin89hq/km43, has not had a workflow start (billing), but the SHA type is checkable without one.

Next step: change the pin to 0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6, the peeled commit, and add a note to the adoption guide that a pin must be the ^{} commit when the tag is annotated. The other three pinned actions in the templates (actions/checkout, actions/setup-node, extractions/setup-just) resolve as commits.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions