Skip to content

Pin GitHub Actions to commit#202

Merged
thepwagner merged 1 commit intomainfrom
pin-actions-commit
May 26, 2025
Merged

Pin GitHub Actions to commit#202
thepwagner merged 1 commit intomainfrom
pin-actions-commit

Conversation

@rxbchen
Copy link
Copy Markdown
Contributor

@rxbchen rxbchen commented May 12, 2025

This is an automated PR to update actions in this repo. The operation should be no-op, as we are only switching out the version tag with the matching commit SHA.

To align with industry best practices, we are going to pin Github Actions to a specific commit SHA.

To read more about why pinning actions is recommended check here.

To ensure these Actions stay to-do-date, this PR also enables Dependabot automated updates. To read more about this configuration check here.

Please reach out if you have any questions. This PR will be merged in ~1 week.

@rxbchen rxbchen requested a review from burke as a code owner May 12, 2025 20:28
Copy link
Copy Markdown
Contributor

@thepwagner thepwagner left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Internally we talked about maybe allowlisting certain actions from this process.

Meh as these do not release. very frequently.

@thepwagner thepwagner merged commit 3dd0018 into main May 26, 2025
2 checks passed
@thepwagner thepwagner deleted the pin-actions-commit branch May 26, 2025 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants