Skip to content

chore(deps): update launchdarkly/gh-actions digest to 5adb11f#1170

Merged
joker23 merged 1 commit into
mainfrom
renovate/launchdarkly-gh-actions-digest
Mar 11, 2026
Merged

chore(deps): update launchdarkly/gh-actions digest to 5adb11f#1170
joker23 merged 1 commit into
mainfrom
renovate/launchdarkly-gh-actions-digest

Conversation

@renovate

@renovate renovate Bot commented Mar 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
launchdarkly/gh-actions action digest bbbbbda5adb11f

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from a team as a code owner March 10, 2026 21:40
@github-actions

Copy link
Copy Markdown
Contributor

@launchdarkly/js-sdk-common size report
This is the brotli compressed size of the ESM build.
Compressed size: 25566 bytes
Compressed size limit: 26000
Uncompressed size: 125383 bytes

@github-actions

Copy link
Copy Markdown
Contributor

@launchdarkly/js-client-sdk size report
This is the brotli compressed size of the ESM build.
Compressed size: 24212 bytes
Compressed size limit: 25000
Uncompressed size: 83755 bytes

@github-actions

Copy link
Copy Markdown
Contributor

@launchdarkly/browser size report
This is the brotli compressed size of the ESM build.
Compressed size: 172130 bytes
Compressed size limit: 200000
Uncompressed size: 800872 bytes

@github-actions

Copy link
Copy Markdown
Contributor

@launchdarkly/js-client-sdk-common size report
This is the brotli compressed size of the ESM build.
Compressed size: 21281 bytes
Compressed size limit: 24000
Uncompressed size: 110213 bytes

run: yarn workspaces focus ${{ inputs.workspace_name }}

- uses: launchdarkly/gh-actions/actions/release-secrets@bbbbbda684f500766264e7fe327668094ba83d1c
- uses: launchdarkly/gh-actions/actions/release-secrets@5adb11fd6953e1bc35d9cf1fc1b4374c464e3a8b

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This SHA isn't for a release of release-secrets, but is just main. Where the original SHA is a release.

@renovate renovate Bot force-pushed the renovate/launchdarkly-gh-actions-digest branch from f7122ad to afee76a Compare March 11, 2026 14:51

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

ssm_parameter_pairs: '/sdk/common/hello-apps/client-key = LAUNCHDARKLY_CLIENT_SIDE_ID'

- uses: launchdarkly/gh-actions/actions/release-secrets@bbbbbda684f500766264e7fe327668094ba83d1c
- uses: launchdarkly/gh-actions/actions/release-secrets@5adb11fd6953e1bc35d9cf1fc1b4374c464e3a8b

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action pinned to non-release main branch commit

Medium Severity

The digest 5adb11fd6953e1bc35d9cf1fc1b4374c464e3a8b resolves to an arbitrary main branch commit rather than a tagged release of launchdarkly/gh-actions/actions/release-secrets. Pinning to an unversioned commit means the action's behavior isn't tied to a stable, reviewed release, which undermines the supply-chain security guarantees that digest pinning is meant to provide. The original digest bbbbbda684f500766264e7fe327668094ba83d1c was a release SHA.

Fix in Cursor Fix in Web

@joker23 joker23 merged commit 2b9c49c into main Mar 11, 2026
43 checks passed
@joker23 joker23 deleted the renovate/launchdarkly-gh-actions-digest branch March 11, 2026 15:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants