Skip to content

Tighten sha-pin's Local-Ref Skip: Bare .github/ and Quoted Refs #1889

Description

@ptr727

Finding

check_sha_pin in .github/actions/repo-gate/repo_gate.py decides which uses: refs to skip with ref.startswith(("$/", "./", ".github/")) on the raw USES capture. Two gaps follow.

  1. A bare .github/ prefix is skipped, although GitHub does not accept it as a local path. Only ./ (and $/) mark a repository path, so uses: .github/actions/build is parsed as {owner}/{repo}[/path]@ref and fails at run time. The check skips it before the "has no ref at all" test that would have caught it, so the gate passes a workflow that breaks when it runs.
  2. A quoted local ref is not recognized. The capture keeps quotes, so uses: "./.github/actions/build" fails the startswith test and is reported as having no ref at all, a false positive on a valid local reference.

Suggested fix

Drop .github/ from the skip tuple, or report it as a malformed ref, and strip surrounding quotes from the capture before testing the prefix. Update the docstring and the scripts/README.md sha-pin bullet, which currently describe the bare .github/ skip as unvalidated, to match.

Found by a local strict review on the pull request for #1886, outside that change's scope.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions