Skip to content

ci: pin claude-code-action to a SHA in claude-code-review.yml - #112

Draft
jnasbyupgrade wants to merge 1 commit into
Postgres-Extensions:masterfrom
jnasbyupgrade:pin-action-shas
Draft

ci: pin claude-code-action to a SHA in claude-code-review.yml#112
jnasbyupgrade wants to merge 1 commit into
Postgres-Extensions:masterfrom
jnasbyupgrade:pin-action-shas

Conversation

@jnasbyupgrade

@jnasbyupgrade jnasbyupgrade commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Summary

  • claude-code-review.yml's job runs as pull_request_target with pull-requests: write, so a moved upstream tag must not silently change what code runs -- the same reasoning already applied to github-script's SHA pin in ci.yml/protect-label.yml (see those comments). claude-code-action was the one action in this trust class still tracking a mutable tag (@v1) instead of a SHA.
  • actions/checkout (here and elsewhere) and claude.yml's own claude-code-action@v1 stay on tags deliberately -- existing comments already explain why ("so upstream fixes are picked up automatically"); checkout only reads the base branch, and claude.yml runs under a narrower trust boundary (actor-gated, read-only permissions), not pull_request_target with write access. This PR doesn't touch either.

Companion pgxntool-test PR: Postgres-Extensions/pgxntool-test#80

This job runs as pull_request_target with pull-requests: write, so a moved
upstream tag must not silently change what code runs -- the same reasoning
already applied to github-script's pin in ci.yml/protect-label.yml (see
those comments). claude-code-action was the one action in this trust class
still tracking a mutable tag (@v1) instead of a SHA.

`actions/checkout` and claude.yml's own claude-code-action@v1 stay on tags
deliberately (existing comments: "so upstream fixes are picked up
automatically") -- checkout only reads the base branch, and claude.yml runs
under a much narrower trust boundary (actor-gated, read-only permissions),
not pull_request_target with write access. This change doesn't touch either.

Related changes in pgxntool-test:
- Same fix, same rationale, mirrored in its own claude-code-review.yml

Co-Authored-By: Claude <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 3b98993d-dc8e-4309-8f39-8b1b93ea8f99

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant