Skip to content

SHA pining of GitHub Actions and auto dependabot updates for them#4

Merged
inxilpro merged 2 commits into
mainfrom
sha-pinining-and-dependabot-updates
May 13, 2026
Merged

SHA pining of GitHub Actions and auto dependabot updates for them#4
inxilpro merged 2 commits into
mainfrom
sha-pinining-and-dependabot-updates

Conversation

@Orrison
Copy link
Copy Markdown
Collaborator

@Orrison Orrison commented May 13, 2026

Updates GitHub Actions workflows to improve reliability and security by pinning all action dependencies to specific commit SHAs and updating some action versions.

It also introduces a Dependabot configuration for automated updates of these SHAs as long as the updates are outside of the 7 day cooldown. (unless GitHub determines it a security update)

This will help keep the GitHub actions updates and protect against supply-chain attacks on the tag names.

Orrison added 2 commits May 12, 2026 22:31
Signed-off-by: Kevin Ullyott <kevin.ullyott@canyongbs.com>
Signed-off-by: Kevin Ullyott <kevin.ullyott@canyongbs.com>
@Orrison Orrison requested a review from inxilpro May 13, 2026 02:35
@inxilpro inxilpro merged commit 8491a89 into main May 13, 2026
25 checks passed
@Orrison Orrison deleted the sha-pinining-and-dependabot-updates branch May 13, 2026 19:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants