patch: updating to pin actions to their current version commit hashes - #202
Open
walteck wants to merge 2 commits into
Open
patch: updating to pin actions to their current version commit hashes#202walteck wants to merge 2 commits into
walteck wants to merge 2 commits into
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
Pins GitHub Actions used in CI and docs workflows to immutable commit SHAs to reduce supply-chain risk and improve build reproducibility.
Changes:
- Pinned
actions/checkout,actions/setup-python,actions/setup-go, and several third-party actions to specific commit SHAs. - Added inline comments noting the corresponding action version tags for readability/traceability.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| .github/workflows/docs-pipeline.yaml | Pins some actions to SHAs for the docs deployment workflow (but one uses: remains tag-based). |
| .github/workflows/ci-pipeline.yaml | Pins CI workflow actions (checkout/terraform/go/tflint/semantic-release) to SHAs. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
|
||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Pinned actions to their commit hash - note I haven't attempted to uplift these version to more recent versions.
Type of change
Please check the relevant options:
🔲 New feature (a change which adds functionality)
🔲 Bug fix (a change which fixes an issue)
🔲 Refactoring (code cleanup or optimisation)
🔲 Testing (new tests, or improvements to existing tests)
[x] Pipelines (changes to pipelines and workflows)
🔲 Documentation (changes to documentation)
🔲 Other (something that's not listed here - please explain)
Checklist
Please check the relevant options:
[x] My code aligns with the style of this project
[x] I have added comments in hard to understand areas
🔲 I have added tests that prove my change works
🔲 I have updated the documentation
🔲 If merging into main, I'm aware that the PR should be squash merged with a commit message that adheres to the semantic release format
Additional Information
Please provide any additional information or context related to this pull request.