From c2189b5cbe1b77645a0a2ec191b39909593c75f1 Mon Sep 17 00:00:00 2001 From: GitHub Security Bot <88103841+github-security-bot@users.noreply.github.com> Date: Thu, 10 Sep 2026 17:27:28 -0400 Subject: [PATCH 1/3] Pin GitHub Actions to commit SHAs --- .github/dependabot.yml | 8 ++++++++ .github/workflows/lint.yml | 4 ++-- .github/workflows/release.yml | 4 ++-- .github/workflows/test.yml | 4 ++-- 4 files changed, 14 insertions(+), 6 deletions(-) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..6cc0071 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,8 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + cooldown: + default-days: 7 diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index f8cfb4b..5e21232 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -21,12 +21,12 @@ jobs: steps: - name: Set up Go - uses: actions/setup-go@v2 + uses: actions/setup-go@bfdd3570ce990073878bf10f6b2d79082de49492 # v2.2.0 with: go-version: 1.17 - name: Check out code - uses: actions/checkout@v2 + uses: actions/checkout@0717577d45739eb3c851188b29f50ed6c0b2194e # v2.8.0 - name: Verify dependencies run: | diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index b35a733..7f7a0ae 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -21,14 +21,14 @@ jobs: go-version: 1.21 - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Build releases run: | make releases VERSION=$GITHUB_REF_NAME - name: Release - uses: softprops/action-gh-release@v1 + uses: softprops/action-gh-release@de2c0eb89ae2a093876385947365aca7b0e5f844 # v1 with: draft: true files: | diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 542f410..9d9ea2f 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -12,12 +12,12 @@ jobs: runs-on: ${{ matrix.os }} steps: - name: Set up Go - uses: actions/setup-go@v6 + uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0 with: go-version: '1.21.3' - name: Check out code - uses: actions/checkout@v2 + uses: actions/checkout@0717577d45739eb3c851188b29f50ed6c0b2194e # v2.8.0 - name: Get full repo history run: git fetch --prune --unshallow --tags From e52282d8ca89e7d6b31a85d3580f4a71e63faf58 Mon Sep 17 00:00:00 2001 From: Michael Recachinas Date: Mon, 5 Oct 2026 20:50:04 -0400 Subject: [PATCH 2/3] Pin multiline release setup-go reference Pin the omitted actions/setup-go v4 reference to its resolved commit without changing the Go toolchain or release behavior. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .github/workflows/release.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 7f7a0ae..b1ab621 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -16,7 +16,7 @@ jobs: steps: - name: Setup uses: - actions/setup-go@v4 + actions/setup-go@7b8cf10d4e4a01d4992d18a89f4d7dc5a3e6d6f4 # v4 with: go-version: 1.21 From 417658d7e6a6a0bb7e13967584da1dca693a3fd8 Mon Sep 17 00:00:00 2001 From: Michael Recachinas Date: Mon, 5 Oct 2026 21:35:14 -0400 Subject: [PATCH 3/3] Keep Go 1.21 macOS tests on a compatible runner Use the supported macos-15 image for the macOS leg while retaining its existing check name. macOS 26 dyld rejects Go 1.21.3 internal-linker binaries without LC_UUID; preserve the established Go toolchain instead of bumping it. Keep Linux/Windows runners, all SHA pins, build steps, race tests, timeouts, and matrix coverage unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .github/workflows/test.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 9d9ea2f..745f781 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -9,7 +9,8 @@ jobs: matrix: os: [ubuntu-latest, macos-latest, windows-latest] fail-fast: false - runs-on: ${{ matrix.os }} + # Preserve Go 1.21 coverage: macOS 26 rejects its linker output without LC_UUID. + runs-on: ${{ matrix.os == 'macos-latest' && 'macos-15' || matrix.os }} steps: - name: Set up Go uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0