Skip to content

ci: pin claude-code-action to a SHA in claude-code-review.yml - #80

Merged
jnasbyupgrade merged 1 commit into
Postgres-Extensions:masterfrom
jnasbyupgrade:pin-action-shas
Sep 8, 2026
Merged

ci: pin claude-code-action to a SHA in claude-code-review.yml#80
jnasbyupgrade merged 1 commit into
Postgres-Extensions:masterfrom
jnasbyupgrade:pin-action-shas

Conversation

@jnasbyupgrade

Copy link
Copy Markdown
Contributor

Related pgxntool PR: Postgres-Extensions/pgxntool#112

Summary

  • Same fix, same rationale as the pgxntool PR above: this job runs as pull_request_target with pull-requests: write, so a moved upstream tag must not silently change what code runs -- matching the SHA pin already used for github-script in pgxntool's ci.yml/protect-label.yml. claude-code-action was the one action in this trust class still tracking a mutable tag (@v1).
  • actions/checkout here and claude.yml's own claude-code-action@v1 stay on tags deliberately (existing comments explain why); this PR doesn't touch either.

Same fix, same rationale as pgxntool commit db659c2: this job runs as
pull_request_target with pull-requests: write, so a moved upstream tag must
not silently change what code runs -- matching the SHA-pin already used for
github-script in pgxntool's ci.yml/protect-label.yml. claude-code-action was
the one action in this trust class still tracking a mutable tag (@v1).

`actions/checkout` here and claude.yml's own claude-code-action@v1 stay on
tags deliberately (existing comments: "so upstream fixes are picked up
automatically") -- this doesn't touch either.

Co-Authored-By: Claude <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: e3d899a0-1c58-419a-9efd-8f671a134948

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jnasbyupgrade
jnasbyupgrade marked this pull request as ready for review September 8, 2026 20:31
jnasbyupgrade added a commit to Postgres-Extensions/pgxntool that referenced this pull request Sep 8, 2026
- `claude-code-review.yml`'s job runs as `pull_request_target` with
`pull-requests: write`, so a moved upstream tag must not silently change
what code runs -- the same reasoning already applied to
`github-script`'s SHA pin in `ci.yml`/`protect-label.yml` (see those
comments). `claude-code-action` was the one action in this trust class
still tracking a mutable tag (`@v1`) instead of a SHA.
- `actions/checkout` (here and elsewhere) and `claude.yml`'s own
`claude-code-action@v1` stay on tags deliberately -- existing comments
already explain why ("so upstream fixes are picked up automatically");
`checkout` only reads the base branch, and `claude.yml` runs under a
narrower trust boundary (actor-gated, read-only permissions), not
`pull_request_target` with write access. This PR doesn't touch either.

Companion pgxntool-test PR:
Postgres-Extensions/pgxntool-test#80

Co-authored-by: Claude <noreply@anthropic.com>
@jnasbyupgrade
jnasbyupgrade merged commit 0fdd755 into Postgres-Extensions:master Sep 8, 2026
11 checks passed
@jnasbyupgrade
jnasbyupgrade deleted the pin-action-shas branch September 8, 2026 20:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant