Skip to content

Skip transitive deps in version-ref nudge - #55

Merged
nodeselector merged 1 commit into
mainfrom
nodeselector/skip-version-ref-nudge-transitive
Jun 16, 2026
Merged

nodeselector merged 1 commit into
mainfrom
nodeselector/skip-version-ref-nudge-transitive

Conversation

@nodeselector

Copy link
Copy Markdown
Collaborator

The version-ref nudge ("N actions pinned without a full semver tag") was
surfacing transitive dependencies that the user has no control over. These
refs come from a composite action's action.yml -- the workflow author
can't change them, so the warning is not actionable and just creates noise.

Spotted on github/launch where actions/checkout@v6, actions/setup-go@v6,
and golangci/golangci-lint-action@<sha> were flagged, all pulled in
transitively by a composite action.

Fix: Filter both the terminal nudge (renderVersionRefNudge) and the
JSON finding injection (injectVersionRefFindings) to only include entries
where e.Direct is true. This matches the existing narrowing logic which
already skips transitive deps for the same reason.

Tests:

  • Three new unit tests covering direct-only filtering, all-transitive
    suppression, and JSON finding injection
  • New scenario catalog entry (transitive_version_ref_nudge_suppressed)
    using cli/gh-extension-precompile@v2.1.0 to assert the nudge text
    doesn't appear when all imprecise refs are transitive

The version-ref warning ("N actions pinned without a full semver tag")
was surfacing transitive dependencies the user has no control over —
their refs come from the composite action's action.yml. Filter both
the terminal nudge (renderVersionRefNudge) and the JSON finding
injection (injectVersionRefFindings) to only flag direct deps.
Copilot AI review requested due to automatic review settings June 16, 2026 00:47
GitHub Advanced Security started work on behalf of nodeselector June 16, 2026 00:49 View session
GitHub Advanced Security finished work on behalf of nodeselector June 16, 2026 00:49

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Ready to approve

The direct-only filtering is correctly applied in both terminal and JSON paths and is covered by targeted unit tests plus a scenario test.

Note: this review does not count toward required approvals for merging.

Pull request overview

Reduces noise in the “version-ref nudge” by ensuring it only reports workflow-direct action references, avoiding non-actionable warnings originating from composite actions’ transitive dependencies.

Changes:

  • Filter renderVersionRefNudge output to include only pin.Entry values where Direct == true.
  • Filter injectVersionRefFindings (for --json=findings) to inject version-ref findings only for direct dependencies.
  • Add unit tests plus an integration scenario ensuring the nudge is suppressed when all imprecise refs are transitive.
File summaries
File Description
test/scenarios/catalog.yml Adds a scenario asserting the version-ref nudge is suppressed when only transitive deps have imprecise refs.
cmd/gh-actions-lock/pin_summary.go Skips transitive dependencies when generating the terminal version-ref nudge.
cmd/gh-actions-lock/pin_summary_test.go Adds unit tests covering direct-only filtering and all-transitive suppression for the nudge and JSON findings injection.
cmd/gh-actions-lock/check.go Skips transitive dependencies when injecting version-ref findings into the JSON report.

Copilot's findings

  • Files reviewed: 4/4 changed files
  • Comments generated: 0

Note

Your feedback helps us improve the quality of this feature.
Please use 👍 or 👎 to tell us whether this assessment is correct.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@nodeselector
nodeselector merged commit efaa421 into main Jun 16, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants