ci: pin Protocol verification actions
This commit is contained in:
@@ -20,8 +20,8 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
- uses: actions/checkout@v7
|
||||
- uses: actions/setup-go@v7
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7
|
||||
with:
|
||||
go-version: "1.26.5"
|
||||
cache: true
|
||||
@@ -44,7 +44,7 @@ jobs:
|
||||
runs-on: macos-26
|
||||
timeout-minutes: 30
|
||||
steps:
|
||||
- uses: actions/checkout@v7
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
||||
- name: Assert pinned toolchain
|
||||
shell: bash
|
||||
run: |
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
.PHONY: verify generate proto-lint proto-breaking source-verify scope-verify conformance frame-verify go-test binding-compile strict-contracts clean-generated
|
||||
.PHONY: verify generate proto-lint proto-breaking source-verify scope-verify ci-verify conformance frame-verify go-test binding-compile strict-contracts clean-generated
|
||||
|
||||
PYTHON ?= python3
|
||||
PROTOC ?= protoc
|
||||
@@ -23,6 +23,9 @@ scope-verify:
|
||||
$(PYTHON) -B tools/test_check_scope.py
|
||||
$(PYTHON) -B tools/check_scope.py
|
||||
|
||||
ci-verify:
|
||||
$(PYTHON) -B tools/check_ci_actions.py
|
||||
|
||||
go-test:
|
||||
go test ./gen/go/... ./tests/go
|
||||
|
||||
@@ -45,4 +48,4 @@ frame-verify:
|
||||
clean-generated:
|
||||
$(PYTHON) tools/generate.py --check
|
||||
|
||||
verify: generate proto-lint proto-breaking source-verify scope-verify go-test binding-compile strict-contracts conformance frame-verify clean-generated
|
||||
verify: generate proto-lint proto-breaking source-verify scope-verify ci-verify go-test binding-compile strict-contracts conformance frame-verify clean-generated
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Require immutable commits for third-party Gitea workflow actions."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import pathlib
|
||||
import re
|
||||
|
||||
|
||||
ROOT = pathlib.Path(__file__).resolve().parents[1]
|
||||
USE = re.compile(r"^\s*-\s+uses:\s+([^@\s]+)@([^\s#]+)", re.MULTILINE)
|
||||
|
||||
|
||||
for workflow in sorted((ROOT / ".gitea/workflows").glob("*.y*ml")):
|
||||
for action, revision in USE.findall(workflow.read_text(encoding="utf-8")):
|
||||
if not action.startswith("./") and not re.fullmatch(r"[0-9a-f]{40}", revision):
|
||||
raise SystemExit(f"{workflow.relative_to(ROOT)}: mutable action {action}@{revision}")
|
||||
|
||||
print("Protocol CI action references are immutable")
|
||||
Reference in New Issue
Block a user