fix(ci): pin actions to their commit sha

Floating tags let a compromised or force pushed release change what the workflows execute. Pinning the actions to a
commit sha and restricting the default token to read access limits the blast radius of a supply chain attack. The
outdated ansible-lint and markdownlint-cli2 versions are raised along with the pinning.

The ansible-lint run installs the collections of the molecule scenario, because the scenario is linted as well and
depends on community.docker beside the community.general requirement of the role.

Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
2026-09-10 21:41:34 +02:00
co-authored by Copilot
parent e2f248e28d
commit ee977a8610
3 changed files with 11 additions and 0 deletions
+5
View File
@@ -7,6 +7,9 @@ on:
branches: [ '**' ] branches: [ '**' ]
tags-ignore: [ '**' ] tags-ignore: [ '**' ]
permissions:
contents: read
jobs: jobs:
ansible-lint: ansible-lint:
runs-on: runs-on:
@@ -17,4 +20,6 @@ jobs:
uses: ansible/ansible-lint@665d9e07a1943254d2910faffc106adaf7ea7294 # v26.8.0 uses: ansible/ansible-lint@665d9e07a1943254d2910faffc106adaf7ea7294 # v26.8.0
with: with:
args: "--config-file .ansible-lint" args: "--config-file .ansible-lint"
# The molecule scenario is linted as well, so its collections are required beside the ones of the role.
requirements_file: "molecule/default/collections.yml"
setup_python: "true" setup_python: "true"
+3
View File
@@ -7,6 +7,9 @@ on:
branches: [ '**' ] branches: [ '**' ]
tags-ignore: [ '**' ] tags-ignore: [ '**' ]
permissions:
contents: read
jobs: jobs:
markdown-lint: markdown-lint:
runs-on: runs-on:
+3
View File
@@ -6,6 +6,9 @@ on:
- '**' - '**'
workflow_dispatch: {} workflow_dispatch: {}
permissions:
contents: read
jobs: jobs:
release: release:
name: Release Ansible Role name: Release Ansible Role