Skip to content

Apply Tyler Paxton's review of the Actions GA page - #4130

Merged
matthewhelmke merged 1 commit into
mainfrom
docs-204-tyler-review-followup
Oct 5, 2026
Merged

matthewhelmke merged 1 commit into
mainfrom
docs-204-tyler-review-followup

Conversation

@matthewhelmke

Copy link
Copy Markdown
Collaborator

What this does

Applies Tyler Paxton's review of the Chainguard Actions overview. He commented on #4029 on 10-02; it merged on 10-05 before those comments were addressed, so this is the follow-up (DOCS-204).

Nine requests, all applied. Three of them corrected factual errors on a page that is now live, which is the reason this is worth reviewing promptly rather than batching.

Corrections

A hardened action's dist/ bundle is not rebuilt. The page said Chainguard rebuilds it, and that the rebuild reproduces rather than refreshes the contents. Verified against the catalog: the git blob SHA of dist/index.js in tj-actions-changed-files@v47 and actions-checkout@v6 is identical to upstream at the pinned commit, so the bundle is carried over verbatim. The conclusion the page drew was right — a hardened release ships the same dependency versions as upstream — but the stated mechanism wasn't. Mae Phillips raised this on the intro bullet during #4029 and Tyler caught the same error further down.

Digest pinning covers runs.image, not Dockerfile FROM lines. The page described a single rule covering both. The image case is now specific: for runs.using: docker with a docker:// image, the pipeline resolves the tag and rewrites the reference as image:tag@sha256:<digest>. Confirmed on google-osv-scanner-action@v2.6.0.

Nested actions are swapped for hardened copies, and that is live. The page said references were pinned to upstream SHAs and described the swap as rolling out. In composite actions the reference now points at the hardened copy where one exists. Confirmed: actions-upload-pages-artifact@v5.0.0 calls chainguard-actions/actions-upload-artifact@92725eed # v7.0.0. The three scope limits stay, because coverage still grows as more of the catalog is hardened.

Pinning guidance

SHA pinning now reads as the default rather than an option. The quick start shows a commit SHA with the tag as a comment instead of a bare version tag, and the migration step no longer frames pinning as conditional.

Setup

Guardener also reads an org-wide .chainguard/actions.yaml from the organization's .github repository, which matters for a section aimed at more than a repository or two. Both setup steps now say so and link the org-level configuration reference.

The GitHub App is called the Chainguard App for GA, renamed on this page only. Eight other pages still say "Guardener GitHub App" and are a separate change. References to Guardener as the agent are unchanged, matching Tyler's own suggested wording.

Removed

"What the entitlement controls" is gone at Tyler's request. The egress-allowlist tip it carried already lives on the telemetry page.

Dropping it exposed something that section had been correcting: the preceding line said the entitlement exists "to enable access to the hardened actions hosted at github.com/chainguard-actions", and those repositories are public. That line now states the step without characterizing what the entitlement gates, which avoids both the misleading claim and the explanation Tyler asked us not to publish.

Testing

npm run build completes clean and all pre-commit hooks pass, including the new page-weight check. Verified in the rendered output that every in-page anchor resolves — including the new #replace-the-uses-line-in-each-workflow cross-link — that the cross-page org-level configuration anchor exists, and that nothing links to the removed section.

Not verified

Tyler's observation that Dockerfile FROM lines are unchanged from upstream rests on his own check. Dockerfile-based actions are rare enough that none appeared in a 22-repository sample, so I could not reproduce it independently. It appears only in the scope line, not in the rules this PR rewrote.


Created in collaboration with Claude Code running Claude Opus 5 on 2026-10-05.

Follow-up to #4029, which merged before his comments
were addressed (DOCS-204).

Corrections:

- A hardened action's `dist/` bundle is not rebuilt. Verified: the git
  blob SHA of `dist/index.js` in `tj-actions-changed-files@v47` and
  `actions-checkout@v6` is identical to upstream at the pinned commit,
  so the bundle is carried over verbatim. The page said Chainguard
  rebuilds it and that the rebuild reproduces rather than refreshes the
  contents. The conclusion was right — a hardened release ships the same
  dependency versions as upstream — but the mechanism was wrong. Mae
  Phillips raised this on the first intro bullet and Tyler caught the
  same error here.
- Digest pinning covers `runs.image`, not Dockerfile `FROM` lines. The
  page described one rule for both. The image case is now specific: the
  pipeline resolves the tag and rewrites it as `image:tag@sha256:…`.
- Nested actions in composite actions are swapped for hardened copies,
  not merely pinned to upstream SHAs, and this is live rather than
  rolling out. Verified: `actions-upload-pages-artifact@v5.0.0` calls
  `chainguard-actions/actions-upload-artifact@92725eed # v7.0.0`. The
  three scope limits stay, since coverage still grows with the catalog.

Pinning guidance now reads as the default rather than an option. The
quick start shows a SHA with the tag as a comment, and the migration step
no longer frames pinning as a conditional.

Guardener also reads an org-wide `.chainguard/actions.yaml` from the
organization's `.github` repository, which matters for a section pitched
at more than a repository or two. Both setup steps now say so and link
the org-level configuration reference.

The GitHub App is called the Chainguard App for GA. Renamed on this page
only; the other eight pages that say "Guardener GitHub App" are a
separate change. References to Guardener as the agent are unchanged.

Removed "What the entitlement controls" at Tyler's request. The egress
allowlist tip it carried already lives on the telemetry page. Dropping it
left the preceding line claiming the entitlement exists "to enable access
to" actions that are in fact public, so that line no longer characterizes
what the entitlement gates.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@matthewhelmke
matthewhelmke requested a review from a team as a code owner October 5, 2026 11:19
@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
chainguard-docs-preview Ready Ready Preview Oct 5, 2026 11:20am UTC

Request Review

@netlify

netlify Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for ornate-narwhal-088216 ready!

Name Link
🔨 Latest commit 9616c24
🔍 Latest deploy log https://app.netlify.com/projects/ornate-narwhal-088216/deploys/6ac387d990b8a6000855cdfc
😎 Deploy Preview https://deploy-preview-4130--ornate-narwhal-088216.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@matthewhelmke
matthewhelmke merged commit 035fe35 into main Oct 5, 2026
15 checks passed
@matthewhelmke
matthewhelmke deleted the docs-204-tyler-review-followup branch October 5, 2026 11:26

This branch was successfully deployed

1 active deployment
Preview — 9616c244 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant