generated from actions/typescript-action
-
Notifications
You must be signed in to change notification settings - Fork 25
Open
Description
Would you consider enabling the make releases immutable option on this repo?
If you did, then users of your action could be certain that a pinned version wouldn't change; allowing them pin versions in their workflows without getting flagged by CodeQL and other security checking tools.
This will likely prevent you from having 'latest' type tags (eg. v4), which may not be something you wish to give up.
Metadata
Metadata
Assignees
Labels
No labels