ci: pin third-party workflow actions - #358
Conversation
Pin the remaining third-party workflow actions in tests and PyPI publishing to immutable commit SHAs while preserving version comments for readability.\n\nCo-authored-by: openhands <openhands@all-hands.dev>
Regenerate the SDK skill so the sync-sdk-skill CI check passes on this PR.\n\nCo-authored-by: openhands <openhands@all-hands.dev>
Update the generated skills catalog after syncing the SDK skill.\n\nCo-authored-by: openhands <openhands@all-hands.dev>
|
👋 This PR needs a couple of things fixed before OpenHands can review it:
Push an update once this is addressed and this check re-runs automatically. This is an automated check - no AI was used to generate this comment. |
4 similar comments
|
👋 This PR needs a couple of things fixed before OpenHands can review it:
Push an update once this is addressed and this check re-runs automatically. This is an automated check - no AI was used to generate this comment. |
|
👋 This PR needs a couple of things fixed before OpenHands can review it:
Push an update once this is addressed and this check re-runs automatically. This is an automated check - no AI was used to generate this comment. |
|
👋 This PR needs a couple of things fixed before OpenHands can review it:
Push an update once this is addressed and this check re-runs automatically. This is an automated check - no AI was used to generate this comment. |
|
👋 This PR needs a couple of things fixed before OpenHands can review it:
Push an update once this is addressed and this check re-runs automatically. This is an automated check - no AI was used to generate this comment. |
Why
The
OpenHands/extensionsrepo still had two third-party GitHub Actions referenced through mutable refs. This fixes the extensions-repo portion of OpenHands/OpenHands#14014 by pinning those actions to immutable commit SHAs while preserving human-readable version comments.Summary
astral-sh/setup-uv@v7in.github/workflows/tests.ymlto37802adc94f370d6bfd71619e3f0bf239e1f3b78.pypa/gh-action-pypi-publish@release/v1in.github/workflows/pypi-publish.ymltocef221092ed1bacb1cc03d23a2d87d1d172e277b(v1.14.0).skills/openhands-sdk/SKILL.mdandskills/index.jsto satisfy existing CI sync checks on the current base.Issue Number
OpenHands/OpenHands#14014 - extensions repo workflow-pinning portion. This PR intentionally does not close the broader org-wide tracking issue.
How to Test
.github/workflows/*.ymlfor non-GitHub/non-OpenHandsuses:refs that are not full 40-character SHAs; the scan found none after this change.python scripts/sync_openhands_sdk_skill.py --check.uv run --group test pytest tests/test_skills_catalog.py::TestGeneratedSkillsIndex::test_index_is_up_to_date -q.Video/Screenshots
N/A - CI workflow configuration and generated catalog updates only.
Notes
This PR was created by an AI agent (OpenHands) on behalf of the user.