Repository navigation
Apply Tyler Paxton's review of the Actions GA page - #4130
Merged
Merged
Conversation
Follow-up to #4029, which merged before his comments were addressed (DOCS-204). Corrections: - A hardened action's `dist/` bundle is not rebuilt. Verified: the git blob SHA of `dist/index.js` in `tj-actions-changed-files@v47` and `actions-checkout@v6` is identical to upstream at the pinned commit, so the bundle is carried over verbatim. The page said Chainguard rebuilds it and that the rebuild reproduces rather than refreshes the contents. The conclusion was right — a hardened release ships the same dependency versions as upstream — but the mechanism was wrong. Mae Phillips raised this on the first intro bullet and Tyler caught the same error here. - Digest pinning covers `runs.image`, not Dockerfile `FROM` lines. The page described one rule for both. The image case is now specific: the pipeline resolves the tag and rewrites it as `image:tag@sha256:…`. - Nested actions in composite actions are swapped for hardened copies, not merely pinned to upstream SHAs, and this is live rather than rolling out. Verified: `actions-upload-pages-artifact@v5.0.0` calls `chainguard-actions/actions-upload-artifact@92725eed # v7.0.0`. The three scope limits stay, since coverage still grows with the catalog. Pinning guidance now reads as the default rather than an option. The quick start shows a SHA with the tag as a comment, and the migration step no longer frames pinning as a conditional. Guardener also reads an org-wide `.chainguard/actions.yaml` from the organization's `.github` repository, which matters for a section pitched at more than a repository or two. Both setup steps now say so and link the org-level configuration reference. The GitHub App is called the Chainguard App for GA. Renamed on this page only; the other eight pages that say "Guardener GitHub App" are a separate change. References to Guardener as the agent are unchanged. Removed "What the entitlement controls" at Tyler's request. The egress allowlist tip it carried already lives on the telemetry page. Dropping it left the preceding line claiming the entitlement exists "to enable access to" actions that are in fact public, so that line no longer characterizes what the entitlement gates. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
✅ Deploy Preview for ornate-narwhal-088216 ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this does
Applies Tyler Paxton's review of the Chainguard Actions overview. He commented on #4029 on 10-02; it merged on 10-05 before those comments were addressed, so this is the follow-up (DOCS-204).
Nine requests, all applied. Three of them corrected factual errors on a page that is now live, which is the reason this is worth reviewing promptly rather than batching.
Corrections
A hardened action's
dist/bundle is not rebuilt. The page said Chainguard rebuilds it, and that the rebuild reproduces rather than refreshes the contents. Verified against the catalog: the git blob SHA ofdist/index.jsintj-actions-changed-files@v47andactions-checkout@v6is identical to upstream at the pinned commit, so the bundle is carried over verbatim. The conclusion the page drew was right — a hardened release ships the same dependency versions as upstream — but the stated mechanism wasn't. Mae Phillips raised this on the intro bullet during #4029 and Tyler caught the same error further down.Digest pinning covers
runs.image, not DockerfileFROMlines. The page described a single rule covering both. The image case is now specific: forruns.using: dockerwith adocker://image, the pipeline resolves the tag and rewrites the reference asimage:tag@sha256:<digest>. Confirmed ongoogle-osv-scanner-action@v2.6.0.Nested actions are swapped for hardened copies, and that is live. The page said references were pinned to upstream SHAs and described the swap as rolling out. In composite actions the reference now points at the hardened copy where one exists. Confirmed:
actions-upload-pages-artifact@v5.0.0callschainguard-actions/actions-upload-artifact@92725eed # v7.0.0. The three scope limits stay, because coverage still grows as more of the catalog is hardened.Pinning guidance
SHA pinning now reads as the default rather than an option. The quick start shows a commit SHA with the tag as a comment instead of a bare version tag, and the migration step no longer frames pinning as conditional.
Setup
Guardener also reads an org-wide
.chainguard/actions.yamlfrom the organization's.githubrepository, which matters for a section aimed at more than a repository or two. Both setup steps now say so and link the org-level configuration reference.The GitHub App is called the Chainguard App for GA, renamed on this page only. Eight other pages still say "Guardener GitHub App" and are a separate change. References to Guardener as the agent are unchanged, matching Tyler's own suggested wording.
Removed
"What the entitlement controls" is gone at Tyler's request. The egress-allowlist tip it carried already lives on the telemetry page.
Dropping it exposed something that section had been correcting: the preceding line said the entitlement exists "to enable access to the hardened actions hosted at
github.com/chainguard-actions", and those repositories are public. That line now states the step without characterizing what the entitlement gates, which avoids both the misleading claim and the explanation Tyler asked us not to publish.Testing
npm run buildcompletes clean and all pre-commit hooks pass, including the new page-weight check. Verified in the rendered output that every in-page anchor resolves — including the new#replace-the-uses-line-in-each-workflowcross-link — that the cross-page org-level configuration anchor exists, and that nothing links to the removed section.Not verified
Tyler's observation that Dockerfile
FROMlines are unchanged from upstream rests on his own check. Dockerfile-based actions are rare enough that none appeared in a 22-repository sample, so I could not reproduce it independently. It appears only in the scope line, not in the rules this PR rewrote.Created in collaboration with Claude Code running Claude Opus 5 on 2026-10-05.