Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Reference actions by commit SHA (#224)
* Ref actions by commit SHA in codeql-analysis.yml It's important to make sure the SHA's are from the original repositories and not forks. For reference: https://github.com/actions/cache/releases/tag/v3.3.1 actions/cache@88522ab https://github.com/actions/checkout/releases/tag/v3.5.2 actions/checkout@8e5e7e5 https://github.com/github/codeql-action/releases/tag/v2.3.6 https://github.com/github/codeql-action/commit/83f0fe6c4988d98a455712a27f0255212bba9bd4 Signed-off-by: Gabriela Gutierrez <gabigutierrez@google.com> * Ref actions by commit SHA in coverage.yml It's important to make sure the SHA's are from the original repositories and not forks. For reference: https://github.com/actions/cache/releases/tag/v3.3.1 actions/cache@88522ab https://github.com/actions/checkout/releases/tag/v3.5.2 actions/checkout@8e5e7e5 https://github.com/actions/setup-java/releases/tag/v3.11.0 https://github.com/actions/setup-java/commit/5ffc13f4174014e2d4d4572b3d74c3fa61aeb2c2 https://github.com/codecov/codecov-action/releases/tag/v3.1.4 codecov/codecov-action@eaaf4be Signed-off-by: Gabriela Gutierrez <gabigutierrez@google.com> * Ref actions by commit SHA in maven.yml It's important to make sure the SHA's are from the original repositories and not forks. For reference: https://github.com/actions/cache/releases/tag/v3.3.1 actions/cache@88522ab https://github.com/actions/checkout/releases/tag/v3.5.2 actions/checkout@8e5e7e5 https://github.com/actions/setup-java/releases/tag/v3.11.0 https://github.com/actions/setup-java/commit/5ffc13f4174014e2d4d4572b3d74c3fa61aeb2c2 Signed-off-by: Gabriela Gutierrez <gabigutierrez@google.com> * Ref actions by commit SHA in scorecards-analysis.yml It's important to make sure the SHA's are from the original repositories and not forks. For reference: https://github.com/actions/checkout/releases/tag/v3.5.2 actions/checkout@8e5e7e5 Signed-off-by: Gabriela Gutierrez <gabigutierrez@google.com> --------- Signed-off-by: Gabriela Gutierrez <gabigutierrez@google.com>
- Loading branch information