Skip to content

chore: supply chain hardening#428

Merged
grandizzy merged 1 commit into
mainfrom
georgen/supply-chain-hardening
Apr 15, 2026
Merged

chore: supply chain hardening#428
grandizzy merged 1 commit into
mainfrom
georgen/supply-chain-hardening

Conversation

@decofe
Copy link
Copy Markdown
Member

@decofe decofe commented Apr 14, 2026

  • Add SHA256 checksum verification for actionlint binary download in workflow-validation.yml (matching the pattern used for changelogs)
  • Pin tempo-alloy and tempo-primitives git deps to rev = 7d809cf3 to prevent silent drift on cargo update
  • Bump rand 0.9.2 → 0.9.4 (fixes RUSTSEC-2026-0097)

Prompted by: georgen

- Add SHA256 checksum verification for actionlint binary download
- Pin tempo git deps to rev in Cargo.toml to prevent drift
- Bump rand 0.9.2 → 0.9.4 (fixes RUSTSEC-2026-0097)

Co-authored-by: grandizzy <38490174+grandizzy@users.noreply.github.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019d8bbf-b195-74f8-a054-7f51e5ea9f9a
@github-actions
Copy link
Copy Markdown
Contributor

⚠️ Changelog not found.

A changelog entry is required before merging.

Add changelog

@grandizzy grandizzy marked this pull request as ready for review April 14, 2026 12:58
@grandizzy grandizzy merged commit 265efc6 into main Apr 15, 2026
14 checks passed
@grandizzy grandizzy deleted the georgen/supply-chain-hardening branch April 15, 2026 05:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants