Repository navigation
Skip transitive deps in version-ref nudge - #55
Merged
nodeselector merged 1 commit intoJun 16, 2026
Merged
Conversation
The version-ref warning ("N actions pinned without a full semver tag")
was surfacing transitive dependencies the user has no control over —
their refs come from the composite action's action.yml. Filter both
the terminal nudge (renderVersionRefNudge) and the JSON finding
injection (injectVersionRefFindings) to only flag direct deps.
There was a problem hiding this comment.
✅ Ready to approve
The direct-only filtering is correctly applied in both terminal and JSON paths and is covered by targeted unit tests plus a scenario test.
Note: this review does not count toward required approvals for merging.
Pull request overview
Reduces noise in the “version-ref nudge” by ensuring it only reports workflow-direct action references, avoiding non-actionable warnings originating from composite actions’ transitive dependencies.
Changes:
- Filter
renderVersionRefNudgeoutput to include onlypin.Entryvalues whereDirect == true. - Filter
injectVersionRefFindings(for--json=findings) to inject version-ref findings only for direct dependencies. - Add unit tests plus an integration scenario ensuring the nudge is suppressed when all imprecise refs are transitive.
File summaries
| File | Description |
|---|---|
| test/scenarios/catalog.yml | Adds a scenario asserting the version-ref nudge is suppressed when only transitive deps have imprecise refs. |
| cmd/gh-actions-lock/pin_summary.go | Skips transitive dependencies when generating the terminal version-ref nudge. |
| cmd/gh-actions-lock/pin_summary_test.go | Adds unit tests covering direct-only filtering and all-transitive suppression for the nudge and JSON findings injection. |
| cmd/gh-actions-lock/check.go | Skips transitive dependencies when injecting version-ref findings into the JSON report. |
Copilot's findings
- Files reviewed: 4/4 changed files
- Comments generated: 0
Note
Your feedback helps us improve the quality of this feature.
Please use 👍 or 👎 to tell us whether this assessment is correct.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The version-ref nudge ("N actions pinned without a full semver tag") was
surfacing transitive dependencies that the user has no control over. These
refs come from a composite action's
action.yml-- the workflow authorcan't change them, so the warning is not actionable and just creates noise.
Spotted on github/launch where
actions/checkout@v6,actions/setup-go@v6,and
golangci/golangci-lint-action@<sha>were flagged, all pulled intransitively by a composite action.
Fix: Filter both the terminal nudge (
renderVersionRefNudge) and theJSON finding injection (
injectVersionRefFindings) to only include entrieswhere
e.Directis true. This matches the existing narrowing logic whichalready skips transitive deps for the same reason.
Tests:
suppression, and JSON finding injection
transitive_version_ref_nudge_suppressed)using
cli/gh-extension-precompile@v2.1.0to assert the nudge textdoesn't appear when all imprecise refs are transitive