Skip to content

Comments

Upgrade GitHub Actions to latest versions#10159

Open
salmanmkc wants to merge 1 commit intoaquasecurity:mainfrom
salmanmkc:upgrade-github-actions-node24-general
Open

Upgrade GitHub Actions to latest versions#10159
salmanmkc wants to merge 1 commit intoaquasecurity:mainfrom
salmanmkc:upgrade-github-actions-node24-general

Conversation

@salmanmkc
Copy link

Summary

Upgrade GitHub Actions to their latest versions for improved features, bug fixes, and security updates.

Changes

Action Old Version(s) New Version Release Files
Skitionek/notify-microsoft-teams e7a2493 41775a4 Release spdx-cron.yaml
docker/login-action 5e57cd1 c94ce9f Release reusable-release.yaml
helm/chart-testing-action 6ec842c 0d28d31 Release publish-chart.yaml
helm/kind-action 92086f6 a1b0e39 Release publish-chart.yaml
sigstore/cosign-installer faadad0 398d4b0 Release reusable-release.yaml

Why upgrade?

Keeping GitHub Actions up to date ensures:

  • Security: Latest security patches and fixes
  • Features: Access to new functionality and improvements
  • Compatibility: Better support for current GitHub features
  • Performance: Optimizations and efficiency improvements

Security Note

Actions that were previously pinned to commit SHAs remain pinned to SHAs (updated to the latest release SHA) to maintain the security benefits of immutable references.

Testing

These changes only affect CI/CD workflow configurations and should not impact application functionality. The workflows should be tested by running them on a branch before merging.

Signed-off-by: Salman Muin Kayser Chishti <13schishti@gmail.com>
@salmanmkc salmanmkc requested a review from knqyf263 as a code owner February 6, 2026 09:19
@CLAassistant
Copy link

CLAassistant commented Feb 6, 2026

CLA assistant check
All committers have signed the CLA.

Copy link
Collaborator

@knqyf263 knqyf263 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the PR. I noticed some discrepancies between the commit SHAs and the version comments that I wanted to flag.

I verified each SHA against the actual release tags, and it looks like several of the updates may have been mixed up:

SHAs pointing to older versions:

Action Current version New SHA Expected version (per comment) Actual version (per SHA)
sigstore/cosign-installer v4.0.0 (faadad0) 398d4b0 v4.0.0 v3.9.1
helm/chart-testing-action v2.8.0 (6ec842c) 0d28d31 v2.8.0 v2.7.0
helm/kind-action v1.13.0 (92086f6) a1b0e39 v1.13.0 v1.12.0

These appear to be downgrades rather than upgrades.

SHA mismatch:

Action New SHA Comment Actual tag SHA for that version
Skitionek/notify-microsoft-teams 41775a4 v1.0.9 11e40c3

The SHA 41775a4 does not correspond to the v1.0.9 tag.

Could you double-check the SHAs and version comments? It's possible something went wrong during the lookup process.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants