Skip to content

✨ Adds support for Actions lock files to detect pinning - #5247

Open
jessehouwing wants to merge 2 commits into
ossf:mainfrom
jessehouwing:main
Open

jessehouwing wants to merge 2 commits into
ossf:mainfrom
jessehouwing:main

Conversation

@jessehouwing

Copy link
Copy Markdown

What kind of change does this PR introduce?

(Is it a bug fix, feature, docs update, something else?)

What is the current behavior?

scorecard only detects pinned actions using @sha, but ignores the new actions lock files, flooding my security tab with 100's of unpinned actions warnins.

What is the new behavior (if this is a feature change)?

  • Tests for the changes have been added (for bug fixes/features)

Now reads an actions.lock if present and resolves pins from it.

Which issue(s) this PR fixes

NONE

Special notes for your reviewer

Generated with copilot, tested against all my own repos on Windows (required additional fixes to make it work on Windows).

Tested on Ubuntu-latest using CI.

Integration tests fail, with a fuzzing error which seems totally unrelated.

Does this PR introduce a user-facing change?

NONE

Adds support for actions lock files for pinning.

@jessehouwing
jessehouwing requested a review from a team as a code owner September 22, 2026 19:05
@jessehouwing
jessehouwing requested review from justaugustus and spencerschrock and removed request for a team September 22, 2026 19:05
@jessehouwing
jessehouwing force-pushed the main branch 2 times, most recently from 02d9f49 to f4957c7 Compare September 24, 2026 11:31
jessehouwing and others added 2 commits October 1, 2026 16:28
- Detect actions pinned via github/gh-actions-lock lockfiles (.github/workflows/actions.lock)
- Treat \\$/...\ self-repository references as inherently pinned
- Fix filepath.Dir/Clean usage on repo-relative (forward-slash) paths in IsWorkflowFile, fileIsInVendorDir, and shell_download_validate
- Fix clients/localdir trimPrefix to correctly normalize paths to forward slashes on Windows, fixing --local scans
- Add .gitattributes to clients/localdir/testdata to prevent CRLF corruption of binary-compared fixtures

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Jesse Houwing <jesse.houwing@gmail.com>
Signed-off-by: Jesse Houwing <jesse.houwing@gmail.com>
@jessehouwing

Copy link
Copy Markdown
Author

@JamieMagee you might be interested in this one as well then

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

1 participant