Finding
check_sha_pin in .github/actions/repo-gate/repo_gate.py decides which uses: refs to skip with ref.startswith(("$/", "./", ".github/")) on the raw USES capture. Two gaps follow.
- A bare
.github/ prefix is skipped, although GitHub does not accept it as a local path. Only ./ (and $/) mark a repository path, so uses: .github/actions/build is parsed as {owner}/{repo}[/path]@ref and fails at run time. The check skips it before the "has no ref at all" test that would have caught it, so the gate passes a workflow that breaks when it runs.
- A quoted local ref is not recognized. The capture keeps quotes, so
uses: "./.github/actions/build" fails the startswith test and is reported as having no ref at all, a false positive on a valid local reference.
Suggested fix
Drop .github/ from the skip tuple, or report it as a malformed ref, and strip surrounding quotes from the capture before testing the prefix. Update the docstring and the scripts/README.md sha-pin bullet, which currently describe the bare .github/ skip as unvalidated, to match.
Found by a local strict review on the pull request for #1886, outside that change's scope.
Finding
check_sha_pinin.github/actions/repo-gate/repo_gate.pydecides whichuses:refs to skip withref.startswith(("$/", "./", ".github/"))on the rawUSEScapture. Two gaps follow..github/prefix is skipped, although GitHub does not accept it as a local path. Only./(and$/) mark a repository path, souses: .github/actions/buildis parsed as{owner}/{repo}[/path]@refand fails at run time. The check skips it before the "has no ref at all" test that would have caught it, so the gate passes a workflow that breaks when it runs.uses: "./.github/actions/build"fails thestartswithtest and is reported as having no ref at all, a false positive on a valid local reference.Suggested fix
Drop
.github/from the skip tuple, or report it as a malformed ref, and strip surrounding quotes from the capture before testing the prefix. Update the docstring and thescripts/README.mdsha-pinbullet, which currently describe the bare.github/skip as unvalidated, to match.Found by a local strict review on the pull request for #1886, outside that change's scope.