Skip to content

Conversation

adityasharad
Copy link
Collaborator

Better for security to fix the commit SHA of the external Action, rather than specifying a branch or tag.

Better for security to fix the commit SHA of the external Action, rather than specifying a branch or tag.
@adityasharad adityasharad requested a review from jf205 December 2, 2020 17:56
Copy link
Contributor

@chrisgavin chrisgavin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 Thanks! I agree we should probably be pinning all third-party actions.

@adityasharad adityasharad merged commit 2484941 into rc/1.26 Dec 2, 2020
@tausbn tausbn deleted the adityasharad/rc/pin-sphinx-version branch May 9, 2022 15:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants