Skip to content

Conversation

@drpy
Copy link
Collaborator

@drpy drpy commented Sep 17, 2025

Hi @mtransier,
I have applied some hardening to build.yml:

  • reference non actions/* actions via commit hash instead of version
  • avoid storing credentials on file system, otherwise every step in a workflow file has access to it

Also added a dependabot.yml, so one can also see PRs when new Github actions are available.

When PR build is green, I could also update the maven-release.yml.

@mtransier mtransier changed the base branch from main to build-hardening September 18, 2025 08:17
@mtransier mtransier merged commit 10e6c51 into anypointcloud:build-hardening Sep 18, 2025
0 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants