Skip to content

Create "v1" tag for automatically following this action's updates without modifying workflows #563

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
rhysd opened this issue May 6, 2024 · 4 comments

Comments

@rhysd
Copy link

rhysd commented May 6, 2024

I'd like to suggest to create a v1 tag for making users automatically follow v1.x.y updates without modifying their workflows like other actions in actions organization doing (e.g. actions/checkout@v4).

I know that Dependabot can automatically maintain the versions of actions used in workflow. But they require PR reviews and some people (including me) would not want to spare time for them.

@GuySartorelli
Copy link

I came here with the intention to create this exact issue.

@MasterOdin
Copy link

@ptrumpis
Copy link

I came here with the intention to create this exact issue.

Same.
I just got an error trying to add actions/add-to-project@v1 to my workflow so I came here to ask nicely if we could get a v1 tag.

@boneskull
Copy link

FWIW, this is contrary to GitHub's own recommendations. Even if you decide you trust the actions team, pinning to a SHA would keep you safe from attacks like this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants