ci: pin GitHub Actions to full-length commit SHAs#101
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughThis PR replaces floating ChangesWorkflow Action Pinning
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Pin all action references to full-length commit SHAs for supply chain security. This is required for the org-level policy: 'Require actions to be pinned to a full-length commit SHA'. Original version tags are preserved as comments for readability. Existing SHA pins are left unchanged.
b77fe1f to
2705895
Compare
Pin all action references to full-length commit SHAs for supply chain security.
This is required for enabling the org-level policy:
Require actions to be pinned to a full-length commit SHA
Original version tags are preserved as comments for readability.
Consider adding Dependabot for GitHub Actions to keep pins updated:
Summary by CodeRabbit