Skip to content

Pin GitHub actions by sha #2865

@vdemeester

Description

@vdemeester

As a best practice, we should pin actions we use by commit SHA. This is the case for some workflows in the organization but not all. This issue is there to track updating those workflow and enable this settings.

Note: with dependabot, it doesn't require too much to update those as dependabot knows how to update.

  • List workflows that are not using full commit SHA
  • Update them
  • Enable that setting
Image

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions