Skip to content

Conversation

@KornevNikita
Copy link
Contributor

It's unsafe to use unpinned action references. See: https://docs.zizmor.sh/audits/#unpinned-uses (note: official github actions can be used unpinned).

It's unsafe to use unpinned action references. See:
https://docs.zizmor.sh/audits/#unpinned-uses
@KornevNikita KornevNikita requested a review from a team as a code owner November 6, 2025 12:37
@aelovikov-intel
Copy link
Contributor

What would dependabot say?

@KornevNikita
Copy link
Contributor Author

What would dependabot say?

Do you mean, is he able to update hashes?

@aelovikov-intel
Copy link
Contributor

Not just update, but also update to hashes and not to a tag.

@KornevNikita
Copy link
Contributor Author

Not just update, but also update to hashes and not to a tag.

According to previous dependabot PRs - it looks like he can, although I'm not 100% sure.

@aelovikov-intel aelovikov-intel merged commit 71abd87 into intel:sycl Nov 6, 2025
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants