actions: Only pin the checkout action to a major version #331
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The
actions/checkout
action is from a trusted source (official GitHub Actions), this is in line with the documentation/examples 0, and it enables us to automatically get useful updates 1:This especially makes sense since we already use this approach for all other included actions [2] (so it's finally consistent as well!). (Note: For 3rd-party actions it could make sense to use a more secure approach (commit SHA) but we don't need any secrets for CI and the sources should be trustable so our current approach should be fine.)
[2]: See
git grep -hoE '[^ ]+@[^ ]+' -- .github/workflows/ | sort -u
See https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions regarding security considerations.