diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 875d75729..afc2df8e5 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -30,7 +30,7 @@ jobs: permissions: contents: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ github.event.pull_request.merge_commit_sha }} - name: Set up uv diff --git a/tests/unit/test_github_release_workflow.py b/tests/unit/test_github_release_workflow.py index 5586b1918..de93a68f9 100644 --- a/tests/unit/test_github_release_workflow.py +++ b/tests/unit/test_github_release_workflow.py @@ -5,12 +5,22 @@ from __future__ import annotations +import re from pathlib import Path REPO_ROOT = Path(__file__).resolve().parents[2] WORKFLOW = REPO_ROOT / ".github" / "workflows" / "release.yml" +def test_release_workflow_pins_actions_to_immutable_commits() -> None: + """Actions with release write permissions must not follow mutable tags.""" + workflow = WORKFLOW.read_text(encoding="utf-8") + action_refs = re.findall(r"\buses:\s*([^\s#]+)", workflow) + + assert action_refs + assert all(re.fullmatch(r"[^@]+@[0-9a-f]{40}", ref) for ref in action_refs) + + def test_release_workflow_publishes_only_labeled_merged_main_prs() -> None: """The PR label is the sole release-qualification signal.""" workflow = WORKFLOW.read_text(encoding="utf-8")