Skip to content

Pin actions/cache#231

Closed
edgarrmondragon wants to merge 1 commit into
pre-commit:mainfrom
edgarrmondragon:pin-gha
Closed

Pin actions/cache#231
edgarrmondragon wants to merge 1 commit into
pre-commit:mainfrom
edgarrmondragon:pin-gha

Conversation

@edgarrmondragon
Copy link
Copy Markdown

@edgarrmondragon edgarrmondragon commented Sep 4, 2025

GitHub recently added support for requiring actions to be pinned to a full-length commit SHA1.

Their changelog doesn't mention that composite actions also fail if their own actions are not pinned, which is the case for this project.

Hope this makes sense. I didn't bump the versions, just added the commit SHAs, using pinact run.

Footnotes

  1. https://github.blog/changelog/2025-08-15-github-actions-policy-now-supports-blocking-and-sha-pinning-actions/

GitHub recently added support for requiring actions to be pinned to a
full-length commit SHA[^1].

Their changelog doesn't mention that composite actions also fail if
their own actions are not pinned, which is the case for this project.

Hope this makes sense. I didn't bump the versions, just added the commit
SHAs, using `pinact run`.

[^1]: https://github.blog/changelog/2025-08-15-github-actions-policy-now-supports-blocking-and-sha-pinning-actions/
@asottile
Copy link
Copy Markdown
Member

asottile commented Sep 4, 2025

search for duplicates next time please

@asottile asottile closed this Sep 4, 2025
@pre-commit pre-commit locked as off-topic and limited conversation to collaborators Sep 4, 2025
@edgarrmondragon edgarrmondragon deleted the pin-gha branch September 4, 2025 12:02
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants