Skip to content

Pin GitHub Actions to commit SHA#858

Merged
ndeloof merged 2 commits intocompose-spec:mainfrom
glours:hardening-gha-workflows
Mar 25, 2026
Merged

Pin GitHub Actions to commit SHA#858
ndeloof merged 2 commits intocompose-spec:mainfrom
glours:hardening-gha-workflows

Conversation

@glours
Copy link
Copy Markdown
Collaborator

@glours glours commented Mar 24, 2026

Pin all action references to full commit SHA instead of mutable version tags. Tag retained as inline comment for readability.

@glours glours requested a review from ndeloof as a code owner March 24, 2026 16:38
@glours glours force-pushed the hardening-gha-workflows branch from a42ef73 to 680c9bd Compare March 24, 2026 16:54
@glours glours enabled auto-merge (rebase) March 24, 2026 17:16
Copy link
Copy Markdown
Member

@thaJeztah thaJeztah left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ndeloof ndeloof disabled auto-merge March 25, 2026 08:53
glours and others added 2 commits March 25, 2026 09:53
Pin all action references to full commit SHA instead of mutable
version tags. Tag retained as inline comment for readability.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
@ndeloof ndeloof force-pushed the hardening-gha-workflows branch from 680c9bd to 33ccc45 Compare March 25, 2026 08:53
@ndeloof ndeloof merged commit b9f4c49 into compose-spec:main Mar 25, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants