Skip to content

Commit 9d63afb

Browse files
authored
chore: remove outdated version tags from GitHub Actions (#457)
## Summary - Removes version comment tags (e.g. `#v4`, `#v5`) from all GitHub Actions workflow files - These tags become incorrect when Dependabot updates the action SHAs - The SHA pins are sufficient for version control ## Context This addresses @domdomegg's comment in #453 about these tags becoming outdated when using Dependabot. The SHAs already provide version pinning, making the comment tags redundant and potentially misleading. ## Changes - Removed version tags from all `uses:` statements in `.github/workflows/*.yml` - No functional changes to workflows
1 parent 05003c5 commit 9d63afb

File tree

4 files changed

+32
-32
lines changed

4 files changed

+32
-32
lines changed

.github/workflows/ci.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -13,15 +13,15 @@ jobs:
1313
runs-on: ubuntu-latest
1414
steps:
1515
- name: Checkout code
16-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v4
16+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
1717

1818
- name: Set up Go
19-
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 #v5
19+
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00
2020
with:
2121
go-version-file: 'go.mod'
2222

2323
- name: Cache Go modules
24-
uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 #v4
24+
uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809
2525
with:
2626
path: |
2727
~/.cache/go-build
@@ -57,15 +57,15 @@ jobs:
5757
runs-on: ubuntu-latest
5858
steps:
5959
- name: Checkout code
60-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v4
60+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
6161

6262
- name: Set up Go
63-
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 #v5
63+
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00
6464
with:
6565
go-version-file: 'go.mod'
6666

6767
- name: Cache Go modules
68-
uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 #v4
68+
uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809
6969
with:
7070
path: |
7171
~/.cache/go-build
@@ -81,7 +81,7 @@ jobs:
8181
run: make test-all
8282

8383
- name: Upload coverage artifacts
84-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 #v4
84+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
8585
with:
8686
name: coverage-report
8787
path: |

.github/workflows/claude.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
actions: read
2727
steps:
2828
- name: Checkout repository
29-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v4
29+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
3030
with:
3131
fetch-depth: 1
3232

.github/workflows/deploy.yml

Lines changed: 15 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -17,29 +17,29 @@ jobs:
1717
packages: write
1818
steps:
1919
- name: Checkout repository
20-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v4
20+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
2121

2222
- name: Set up Docker Buildx
23-
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 #v3
23+
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435
2424

2525
- name: Log in to Container Registry
26-
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 #v3
26+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1
2727
with:
2828
registry: ghcr.io
2929
username: ${{ github.actor }}
3030
password: ${{ secrets.GITHUB_TOKEN }}
3131

3232
- name: Extract metadata
3333
id: meta
34-
uses: docker/metadata-action@c1e51972afc2121e065aed6d45c65596fe445f3f #v5
34+
uses: docker/metadata-action@c1e51972afc2121e065aed6d45c65596fe445f3f
3535
with:
3636
images: ghcr.io/${{ github.repository }}
3737
tags: |
3838
type=sha,prefix=main-{{date 'YYYYMMDD'}}-,enable={{is_default_branch}}
3939
type=raw,value=main,enable={{is_default_branch}}
4040
4141
- name: Build and push Docker image
42-
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 #v5
42+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83
4343
with:
4444
context: .
4545
file: ./Dockerfile
@@ -60,25 +60,25 @@ jobs:
6060
cancel-in-progress: false
6161
steps:
6262
- name: Checkout code
63-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v4
63+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
6464

6565
- name: Setup Go
66-
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 #v5
66+
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00
6767
with:
6868
go-version-file: 'go.mod'
6969

7070
- name: Setup Pulumi
71-
uses: pulumi/actions@cc7494be991dba0978f7ffafaf995b0449a0998e #v6
71+
uses: pulumi/actions@cc7494be991dba0978f7ffafaf995b0449a0998e
7272
with:
7373
pulumi-version: ${{ env.PULUMI_VERSION }}
7474

7575
- name: Authenticate to Google Cloud
76-
uses: google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093 #v2
76+
uses: google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093
7777
with:
7878
credentials_json: ${{ secrets.GCP_STAGING_SERVICE_ACCOUNT_KEY }}
7979

8080
- name: Setup Google Cloud SDK
81-
uses: google-github-actions/setup-gcloud@aa5489c8933f4cc7a4f7d45035b3b1440c9c10db #v2
81+
uses: google-github-actions/setup-gcloud@aa5489c8933f4cc7a4f7d45035b3b1440c9c10db
8282
with:
8383
project_id: mcp-registry-staging
8484
install_components: gke-gcloud-auth-plugin
@@ -99,25 +99,25 @@ jobs:
9999
cancel-in-progress: false
100100
steps:
101101
- name: Checkout code
102-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v4
102+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
103103

104104
- name: Setup Go
105-
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 #v5
105+
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00
106106
with:
107107
go-version-file: 'go.mod'
108108

109109
- name: Setup Pulumi
110-
uses: pulumi/actions@cc7494be991dba0978f7ffafaf995b0449a0998e #v6
110+
uses: pulumi/actions@cc7494be991dba0978f7ffafaf995b0449a0998e
111111
with:
112112
pulumi-version: ${{ env.PULUMI_VERSION }}
113113

114114
- name: Authenticate to Google Cloud
115-
uses: google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093 #v2
115+
uses: google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093
116116
with:
117117
credentials_json: ${{ secrets.GCP_PROD_SERVICE_ACCOUNT_KEY }}
118118

119119
- name: Setup Google Cloud SDK
120-
uses: google-github-actions/setup-gcloud@aa5489c8933f4cc7a4f7d45035b3b1440c9c10db #v2
120+
uses: google-github-actions/setup-gcloud@aa5489c8933f4cc7a4f7d45035b3b1440c9c10db
121121
with:
122122
project_id: mcp-registry-prod
123123
install_components: gke-gcloud-auth-plugin

.github/workflows/release.yml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -14,23 +14,23 @@ jobs:
1414
runs-on: ubuntu-latest
1515
steps:
1616
- name: Checkout
17-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v4
17+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
1818
with:
1919
fetch-depth: 0
2020

2121
- name: Set up Go
22-
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 #v5
22+
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00
2323
with:
2424
go-version-file: 'go.mod'
2525

2626
- name: Install cosign
27-
uses: sigstore/cosign-installer@d58896d6a1865668819e1d91763c7751a165e159 #v3
27+
uses: sigstore/cosign-installer@d58896d6a1865668819e1d91763c7751a165e159
2828

2929
- name: Install Syft
3030
uses: anchore/sbom-action/[email protected]
3131

3232
- name: Run GoReleaser
33-
uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a #v6
33+
uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a
3434
with:
3535
distribution: goreleaser
3636
version: v2.12.0
@@ -43,29 +43,29 @@ jobs:
4343
needs: goreleaser
4444
steps:
4545
- name: Checkout
46-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 #v4
46+
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
4747

4848
- name: Set up Docker Buildx
49-
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 #v3
49+
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435
5050

5151
- name: Log in to Container Registry
52-
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 #v3
52+
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1
5353
with:
5454
registry: ghcr.io
5555
username: ${{ github.actor }}
5656
password: ${{ secrets.GITHUB_TOKEN }}
5757

5858
- name: Extract metadata
5959
id: meta
60-
uses: docker/metadata-action@c1e51972afc2121e065aed6d45c65596fe445f3f #v5
60+
uses: docker/metadata-action@c1e51972afc2121e065aed6d45c65596fe445f3f
6161
with:
6262
images: ghcr.io/${{ github.repository }}
6363
tags: |
6464
type=semver,pattern={{version}}
6565
type=raw,value=latest
6666
6767
- name: Build and push Docker image
68-
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 #v5
68+
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83
6969
with:
7070
context: .
7171
file: ./Dockerfile

0 commit comments

Comments
 (0)