Skip to content

Backport workflow-hardening fix (unpinned-uses) to 5 release branches #2983

Description

@CharlieMCY

Summary

The default branch already hardened .github/workflows/publish-release.yml against the issue(s) below, but 5 release branches still carry it. This proposes the same, minimal, scanner-verified fix for each.

What's flagged (by zizmor)

  • unpinned-uses — actions referenced by mutable tag/branch instead of a pinned commit SHA

Already resolved on the default branch in:

Affected release branches (5)

  • release-acala-2.28.0 (still present as of HEAD adc45f50)
  • release-karura-2.28.0 (still present as of HEAD adc45f50)
  • release-karura-2.27.0 (still present as of HEAD 27673888)
  • release-acala-2.27.0 (still present as of HEAD 27673888)
  • release-acala-2.26.0 (still present as of HEAD 17461df5)

Suggested per-branch patches

Each diff below was checked locally with zizmor and actionlint: the flagged finding(s) are cleared on the affected construct and no new lint or security findings are introduced. (Whitespace is normalized; only security-relevant lines change.)

release-acala-2.28.0 — unpinned-uses

File .github/workflows/publish-release.yml; suggested edits:

  • ~ jobs.$J.steps[id=srtool_build].uses : pin(chevdor/srtool-actions -> target_ref SHA)
--- a/.github/workflows/publish-release.yml
+++ b/.github/workflows/publish-release.yml
@@ -58,7 +58,7 @@
       # Build WASM with Substrate Runtime Tool
       - name: Srtool build
         id: srtool_build
-        uses: chevdor/srtool-actions@v0.9.2
+        uses: chevdor/srtool-actions@48e9baed50ca414936dfac59d34d8b9bbe581abd  # v0.9.2
         env:
           BUILD_OPTS: "--features on-chain-release-build,no-metadata-docs"
         with:
release-karura-2.28.0 — unpinned-uses

File .github/workflows/publish-release.yml; suggested edits:

  • ~ jobs.$J.steps[id=srtool_build].uses : pin(chevdor/srtool-actions -> target_ref SHA)
--- a/.github/workflows/publish-release.yml
+++ b/.github/workflows/publish-release.yml
@@ -58,7 +58,7 @@
       # Build WASM with Substrate Runtime Tool
       - name: Srtool build
         id: srtool_build
-        uses: chevdor/srtool-actions@v0.9.2
+        uses: chevdor/srtool-actions@48e9baed50ca414936dfac59d34d8b9bbe581abd  # v0.9.2
         env:
           BUILD_OPTS: "--features on-chain-release-build,no-metadata-docs"
         with:
release-karura-2.27.0 — unpinned-uses

File .github/workflows/publish-release.yml; suggested edits:

  • ~ jobs.$J.steps[id=srtool_build].uses : pin(chevdor/srtool-actions -> target_ref SHA)
--- a/.github/workflows/publish-release.yml
+++ b/.github/workflows/publish-release.yml
@@ -58,7 +58,7 @@
       # Build WASM with Substrate Runtime Tool
       - name: Srtool build
         id: srtool_build
-        uses: chevdor/srtool-actions@v0.9.2
+        uses: chevdor/srtool-actions@48e9baed50ca414936dfac59d34d8b9bbe581abd  # v0.9.2
         env:
           BUILD_OPTS: "--features on-chain-release-build,no-metadata-docs"
         with:
release-acala-2.27.0 — unpinned-uses

File .github/workflows/publish-release.yml; suggested edits:

  • ~ jobs.$J.steps[id=srtool_build].uses : pin(chevdor/srtool-actions -> target_ref SHA)
--- a/.github/workflows/publish-release.yml
+++ b/.github/workflows/publish-release.yml
@@ -58,7 +58,7 @@
       # Build WASM with Substrate Runtime Tool
       - name: Srtool build
         id: srtool_build
-        uses: chevdor/srtool-actions@v0.9.2
+        uses: chevdor/srtool-actions@48e9baed50ca414936dfac59d34d8b9bbe581abd  # v0.9.2
         env:
           BUILD_OPTS: "--features on-chain-release-build,no-metadata-docs"
         with:
release-acala-2.26.0 — unpinned-uses

File .github/workflows/publish-release.yml; suggested edits:

  • ~ jobs.$J.steps[id=srtool_build].uses : pin(chevdor/srtool-actions -> target_ref SHA)
--- a/.github/workflows/publish-release.yml
+++ b/.github/workflows/publish-release.yml
@@ -69,7 +69,7 @@
       # Build WASM with Substrate Runtime Tool
       - name: Srtool build
         id: srtool_build
-        uses: chevdor/srtool-actions@v0.9.2
+        uses: chevdor/srtool-actions@48e9baed50ca414936dfac59d34d8b9bbe581abd  # v0.9.2
         env:
           BUILD_OPTS: "--features on-chain-release-build,no-metadata-docs"
         with:

Happy to open pull requests instead if that's preferred.

Activity

  1. xlc commented on Jun 30, 2026

    @xlc
    Member

    Thanks for the report. We do not plan to backport this to already released release branches.

    These release-* branches are historical release artifacts, and we do not expect publish-release.yml to be run again from them. For that reason, we avoid modifying released branches unless there is an active rerelease or operational need.

    We will keep workflow hardening focused on master and active/upcoming release branches. Closing this as not planned.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions