Skip to content

Conversation

thpierce
Copy link
Contributor

Add validation step to require commit SHAs instead of version tags for third-party GitHub actions in workflow files. Repo config Require actions to be pinned to a full-length commit SHA will protect against this if we missed any others.

Testing done

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@thpierce thpierce requested a review from a team as a code owner September 22, 2025 21:08
@thpierce thpierce added the skip changelog doesn't need a CHANGELOG entry label Sep 22, 2025
@thpierce thpierce enabled auto-merge (squash) September 22, 2025 21:53
@thpierce thpierce merged commit d464802 into main Sep 22, 2025
10 checks passed
@thpierce thpierce deleted the no-version branch September 22, 2025 22:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip changelog doesn't need a CHANGELOG entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants