fix(github): pin org workflow refs to a sha

zizmor's unpinned-uses flags these @main refs. On public repos that is
reported to code scanning and exits 0, so it never blocked anything. On
private repos zizmor runs in annotations mode, exits non-zero and fails
the required check — correctly, since the finding is real.

Pin to a devtools main sha rather than the multi-runner-build-workflow
v3.1.0 tag: that tag predates #1894, so pinning to it would reintroduce
the code scanning failure on private repos.

terraform manages this content for every repo, so bumping the sha here
propagates on apply.
This commit is contained in:
Zack
2026-08-04 18:32:46 +01:00
parent 203c5d39d8
commit eede3f9190
2 changed files with 2 additions and 2 deletions
@@ -7,6 +7,6 @@ on:
jobs: jobs:
validate-pr-title: validate-pr-title:
name: Validate PR Title (conventional commit) name: Validate PR Title (conventional commit)
uses: immich-app/devtools/.github/workflows/shared-pr-require-conventional-commit.yml@main uses: immich-app/devtools/.github/workflows/shared-pr-require-conventional-commit.yml@203c5d39d83e790e0a0858f6058d82ad7dc2df5d # main
permissions: permissions:
pull-requests: write pull-requests: write
@@ -8,7 +8,7 @@ on:
jobs: jobs:
zizmor: zizmor:
name: Zizmor name: Zizmor
uses: immich-app/devtools/.github/workflows/shared-zizmor.yml@main uses: immich-app/devtools/.github/workflows/shared-zizmor.yml@203c5d39d83e790e0a0858f6058d82ad7dc2df5d # main
permissions: permissions:
actions: read actions: read
contents: read contents: read