Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build: lock gradle actions to specific versions #3073

Merged
merged 1 commit into from
May 22, 2023

Conversation

iBotPeaches
Copy link
Owner

I keep getting folks reaching out that the build script is vulnerable to x/y/z, despite the "v2" tag being moved/pointed to a non-vulnerable version of these dependencies.

So this should cause their automated scripts to realize no issue and save me having to triage the weekly email about security issues.

@iBotPeaches iBotPeaches marked this pull request as ready for review May 22, 2023 10:38
@iBotPeaches iBotPeaches merged commit e53869c into master May 22, 2023
28 checks passed
@iBotPeaches iBotPeaches deleted the lock-gradle-build-action branch May 22, 2023 10:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant