Skip to content

patch: updating to pin actions to their current version commit hashes - #202

Open
walteck wants to merge 2 commits into
mainfrom
chwa1-pin-actions
Open

patch: updating to pin actions to their current version commit hashes#202
walteck wants to merge 2 commits into
mainfrom
chwa1-pin-actions

Conversation

@walteck

@walteck walteck commented Jul 24, 2026

Copy link
Copy Markdown

Description

Pinned actions to their commit hash - note I haven't attempted to uplift these version to more recent versions.

Type of change

Please check the relevant options:

🔲 New feature (a change which adds functionality)
🔲 Bug fix (a change which fixes an issue)
🔲 Refactoring (code cleanup or optimisation)
🔲 Testing (new tests, or improvements to existing tests)
[x] Pipelines (changes to pipelines and workflows)
🔲 Documentation (changes to documentation)
🔲 Other (something that's not listed here - please explain)

Checklist

Please check the relevant options:

[x] My code aligns with the style of this project
[x] I have added comments in hard to understand areas
🔲 I have added tests that prove my change works
🔲 I have updated the documentation
🔲 If merging into main, I'm aware that the PR should be squash merged with a commit message that adheres to the semantic release format

Additional Information

Please provide any additional information or context related to this pull request.

Copilot AI review requested due to automatic review settings July 24, 2026 14:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins GitHub Actions used in CI and docs workflows to immutable commit SHAs to reduce supply-chain risk and improve build reproducibility.

Changes:

  • Pinned actions/checkout, actions/setup-python, actions/setup-go, and several third-party actions to specific commit SHAs.
  • Added inline comments noting the corresponding action version tags for readability/traceability.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
.github/workflows/docs-pipeline.yaml Pins some actions to SHAs for the docs deployment workflow (but one uses: remains tag-based).
.github/workflows/ci-pipeline.yaml Pins CI workflow actions (checkout/terraform/go/tflint/semantic-release) to SHAs.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.


steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
Copilot AI review requested due to automatic review settings July 24, 2026 14:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated no new comments.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants