Skip to content

Pin GitHub workflow actions to release SHAs#128

Merged
bartul merged 2 commits into
masterfrom
dependabot-github_actions-azure-webapps-deploy-3.0.8
May 12, 2026
Merged

Pin GitHub workflow actions to release SHAs#128
bartul merged 2 commits into
masterfrom
dependabot-github_actions-azure-webapps-deploy-3.0.8

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 12, 2026

Summary

  • Pin workflow action references to immutable release SHAs across CI, repo configuration enforcement, and Azure deployment workflows.
  • Keep source release comments next to each SHA for maintainability.
  • Pin azure/webapps-deploy to v2.2.19, the latest published release currently reported by GitHub release metadata and Marketplace.

Security Review

  • Reviewed upstream release metadata and repository security pages for actions/checkout, actions/setup-dotnet, actions/cache, actions/upload-artifact, actions/download-artifact, and Azure/webapps-deploy.
  • No published GitHub security advisories were found for those upstream action repositories during review.
  • Resolved SHAs from official upstream release refs before pinning.

Validation

  • Parsed all workflow YAML files successfully.
  • Verified workflow uses: references are SHA-pinned.
  • Ran dotnet build Imperium.slnx successfully with 0 warnings and 0 errors.
  • actionlint was not available locally.

@dependabot dependabot Bot added the chore label May 12, 2026
@dependabot dependabot Bot requested a review from bartul as a code owner May 12, 2026 18:44
@bartul bartul changed the title chore: Bump azure/webapps-deploy from 3 to 3.0.8 Pin GitHub workflow actions to release SHAs May 12, 2026
dependabot Bot and others added 2 commits May 12, 2026 22:55
Bumps [azure/webapps-deploy](https://github.com/azure/webapps-deploy) from 3 to 3.0.8.
- [Release notes](https://github.com/azure/webapps-deploy/releases)
- [Commits](Azure/webapps-deploy@v3...v3.0.8)

---
updated-dependencies:
- dependency-name: azure/webapps-deploy
  dependency-version: 3.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@bartul bartul force-pushed the dependabot-github_actions-azure-webapps-deploy-3.0.8 branch from 0ea5f1e to 999f9f7 Compare May 12, 2026 20:55
@bartul bartul merged commit 71f79d0 into master May 12, 2026
1 check passed
@bartul bartul deleted the dependabot-github_actions-azure-webapps-deploy-3.0.8 branch May 12, 2026 20:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant