Skip to content

Conversation

Copy link
Contributor

Copilot AI commented Nov 20, 2025

Updated all actions/checkout action references to use commit hashes instead of version tags for improved security and reproducibility.

Changes

  • Replaced actions/checkout@v6 with actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0 in:
    • .github/workflows/cibuildwheel.yml
    • .github/workflows/build-linux-arm.yml
    • .github/workflows/build-linux.yml
    • .github/workflows/build-macos.yaml
    • .github/workflows/pre-commit.yml

This aligns all workflow files with the existing pattern in .github/workflows/skywalking-eyes.yml and prevents potential tag hijacking attacks.


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

Copilot AI self-assigned this Nov 20, 2025
Co-authored-by: mihaic <165546+mihaic@users.noreply.github.com>
Copilot AI changed the title [WIP] Update actions/checkout action to v6 Use commit hashes for actions/checkout references Nov 20, 2025
Copilot AI requested a review from mihaic November 20, 2025 18:31
Copilot finished work on behalf of mihaic November 20, 2025 18:31
@mihaic mihaic marked this pull request as ready for review November 20, 2025 18:33
@mihaic mihaic merged commit b9542af into renovate/actions-checkout-6.x Nov 20, 2025
1 check passed
@mihaic mihaic deleted the copilot/sub-pr-228 branch November 20, 2025 18:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants