ci: pin Protocol verification actions
Verify Protocol / module (push) Successful in 26s
Verify Protocol / verify (push) Canceled after 0s

This commit is contained in:
sechmachine
2026-07-30 18:33:35 +07:00
parent 03e14a9ae3
commit d1d00d6472
3 changed files with 27 additions and 5 deletions
+3 -3
View File
@@ -20,8 +20,8 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 10 timeout-minutes: 10
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- uses: actions/setup-go@v7 - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7
with: with:
go-version: "1.26.5" go-version: "1.26.5"
cache: true cache: true
@@ -44,7 +44,7 @@ jobs:
runs-on: macos-26 runs-on: macos-26
timeout-minutes: 30 timeout-minutes: 30
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: Assert pinned toolchain - name: Assert pinned toolchain
shell: bash shell: bash
run: | run: |
+5 -2
View File
@@ -1,4 +1,4 @@
.PHONY: verify generate proto-lint proto-breaking source-verify scope-verify conformance frame-verify go-test binding-compile strict-contracts clean-generated .PHONY: verify generate proto-lint proto-breaking source-verify scope-verify ci-verify conformance frame-verify go-test binding-compile strict-contracts clean-generated
PYTHON ?= python3 PYTHON ?= python3
PROTOC ?= protoc PROTOC ?= protoc
@@ -23,6 +23,9 @@ scope-verify:
$(PYTHON) -B tools/test_check_scope.py $(PYTHON) -B tools/test_check_scope.py
$(PYTHON) -B tools/check_scope.py $(PYTHON) -B tools/check_scope.py
ci-verify:
$(PYTHON) -B tools/check_ci_actions.py
go-test: go-test:
go test ./gen/go/... ./tests/go go test ./gen/go/... ./tests/go
@@ -45,4 +48,4 @@ frame-verify:
clean-generated: clean-generated:
$(PYTHON) tools/generate.py --check $(PYTHON) tools/generate.py --check
verify: generate proto-lint proto-breaking source-verify scope-verify go-test binding-compile strict-contracts conformance frame-verify clean-generated verify: generate proto-lint proto-breaking source-verify scope-verify ci-verify go-test binding-compile strict-contracts conformance frame-verify clean-generated
+19
View File
@@ -0,0 +1,19 @@
#!/usr/bin/env python3
"""Require immutable commits for third-party Gitea workflow actions."""
from __future__ import annotations
import pathlib
import re
ROOT = pathlib.Path(__file__).resolve().parents[1]
USE = re.compile(r"^\s*-\s+uses:\s+([^@\s]+)@([^\s#]+)", re.MULTILINE)
for workflow in sorted((ROOT / ".gitea/workflows").glob("*.y*ml")):
for action, revision in USE.findall(workflow.read_text(encoding="utf-8")):
if not action.startswith("./") and not re.fullmatch(r"[0-9a-f]{40}", revision):
raise SystemExit(f"{workflow.relative_to(ROOT)}: mutable action {action}@{revision}")
print("Protocol CI action references are immutable")