chore: Pin third-party GitHub Actions to full commit SHAs#30
Conversation
Original prompt from will.porter
|
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
Greptile SummaryThis PR pins all third-party GitHub Actions references in Confidence Score: 5/5Safe to merge — purely a supply-chain hardening change with no logic modifications. All changes replace mutable tag references with verified immutable commit SHAs. No functional logic, permissions, or secrets handling is altered. SHAs are confirmed to correspond to the correct v4 releases. No files require special attention. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[GitHub Event\npush / PR / release] --> B[Runner starts]
B --> C["actions/checkout\n@34e114876b0b... #v4"]
C --> D["pnpm/action-setup\n@b906affcce14... #v4"]
D --> E["actions/setup-node\n@49933ea5288c... #v4"]
E --> F[Install / Build / Test / Publish]
style C fill:#d4edda,stroke:#28a745
style D fill:#d4edda,stroke:#28a745
style E fill:#d4edda,stroke:#28a745
Reviews (3): Last reviewed commit: "Fix formatting in workflow files" | Re-trigger Greptile |
Co-Authored-By: will.porter <will.porter@workos.com>
Third-Party Action SHA Age Report
|
Co-Authored-By: will.porter <will.porter@workos.com>
file:///home/ubuntu/pin-actions/authkit-session_pr_body.md
Link to Devin session: https://app.devin.ai/sessions/add87be2227046f198fbac38a32e5358