◐ Shell
reader mode source ↗
Skip to content

gh-109110: Hash-pin GitHub Actions#109111

Closed
pnacht wants to merge 2 commits into
python:mainfrom
pnacht:pinned-gha
Closed

gh-109110: Hash-pin GitHub Actions#109111
pnacht wants to merge 2 commits into
python:mainfrom
pnacht:pinned-gha

Conversation

@pnacht

@pnacht pnacht commented Sep 7, 2023

Copy link
Copy Markdown

Fixes #109110.

This PR hash-pins all GitHub Actions and configures dependabot to keep them up-to-date with a single monthly PR. This will increase the resiliency of the repo's workflows in the face of broken or malicious versions of any Actions.

I don't believe this change requires a NEWS entry, but let me know and I'll add one.

Signed-off-by: Pedro Kaj Kjellerup Nacht <pnacht@google.com>
Signed-off-by: Pedro Kaj Kjellerup Nacht <pnacht@google.com>
@ghost

ghost commented Sep 7, 2023

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.
CLA signed

@bedevere-bot

Copy link
Copy Markdown

Most changes to Python require a NEWS entry.

Please add it using the blurb_it web app or the blurb command-line tool.

@hugovk

hugovk commented Sep 13, 2023

Copy link
Copy Markdown
Member

Thanks for the PR, closing per discussion in #109110.

@hugovk hugovk closed this Sep 13, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Hash-pin GitHub Actions to increase workflow resiliency

5 participants