Skip to content

ci: pin actions to SHAs and untrack local Claude settings - #4

Merged
mitodrummer merged 2 commits into
mainfrom
harden
Sep 16, 2026
Merged

mitodrummer merged 2 commits into
mainfrom
harden

Conversation

@mitodrummer

@mitodrummer mitodrummer commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

Two of the pre-public items from #1's checklist.

Actions pinned to commit SHAs. actions/checkout (v7.0.1), actions/cache (v6.1.0) and wagoid/commitlint-github-action (v6.2.1), each with the release in a trailing comment so Dependabot can bump them. The checkout and cache majors move from v4, which also clears the Node 20 deprecation warning on every run. persist-credentials: false on the three checkouts in ci.yml; commitlint.yml already had it. Dependabot gets a seven-day cooldown for both ecosystems. zizmor .github/workflows reports no findings.

.claude/settings.local.json untracked and ignored: it is a per-developer permissions file.

Once this merges, the repo setting Require actions to be pinned to a full-length commit SHA can be turned on without breaking CI.

🤖 Generated with Claude Code

https://claude.ai/code/session_01HYsh5vYW7fVEvRFTRiJ4h8

Summary by CodeRabbit

  • Chores

    • Improved automated dependency update scheduling.
    • Strengthened CI and commit validation reliability by using fixed action versions.
    • Improved workflow security by preventing unnecessary credential persistence during checks.
    • Updated repository configuration to keep local development settings out of version control.
  • Impact

    • No user-facing product features or behavior changes are included in this update.

mitodrummer and others added 2 commits September 16, 2026 21:05
Every `uses:` now names a full commit with the release in a comment, so
a moved tag cannot change what runs here; Dependabot keeps the pins
current with a seven-day cooldown. `persist-credentials: false` on the
checkouts in ci.yml, matching commitlint.yml. zizmor reports nothing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HYsh5vYW7fVEvRFTRiJ4h8
@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: 9037fb13-5611-4440-ad03-ae503e4499db

📥 Commits

Reviewing files that changed from the base of the PR and between 8047237 and 091469e.

📒 Files selected for processing (5)
  • .claude/settings.local.json
  • .github/dependabot.yml
  • .github/workflows/ci.yml
  • .github/workflows/commitlint.yml
  • .gitignore
💤 Files with no reviewable changes (1)
  • .claude/settings.local.json

Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

The pull request pins GitHub Actions to commit SHAs, disables checkout credential persistence in CI, adds Dependabot cooldowns, and removes and ignores local Claude settings.

Changes

Automation and local configuration hardening

Layer / File(s) Summary
Pin workflow actions
.github/workflows/ci.yml, .github/workflows/commitlint.yml
CI and commitlint replace mutable action tags with commit-pinned references. CI checkout steps disable credential persistence.
Configure update cooldowns
.github/dependabot.yml
GitHub Actions and Cargo updates use a seven-day default cooldown.
Handle local Claude settings
.claude/settings.local.json, .gitignore
The local Claude settings file is removed, and its path is added to .gitignore.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested reviewers: evanspearman

Merge Risk: ⚪ Minimal · up to 09146

The hardening changes do not introduce an identified workflow or repository-hygiene risk and are ready to merge.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the two main changes: pinning GitHub Actions to commit SHAs and untracking local Claude settings. It is concise and follows the repository's Conventional Commit format.
Description check ✅ Passed The description provides a detailed summary and includes testing information for zizmor. It does not reproduce the Testing and Checklist headings or provide just check output, but it is mostly compl…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

A rabbit reads each line,
The patch grows clear beneath the moon,
Small changes hop in place,
Tests guard the garden path,
Reviews bloom before the dawn.

Comment @coderabbitai help to get the list of available commands.

@mitodrummer
mitodrummer merged commit 983982d into main Sep 16, 2026
5 checks passed
@mitodrummer
mitodrummer deleted the harden branch September 16, 2026 21:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants