Skip to content

ci: pin github actions hashes#1

Merged
mbaraniak-exodus merged 1 commit into
masterfrom
mbaraniak/github-action-pinning
May 6, 2026
Merged

ci: pin github actions hashes#1
mbaraniak-exodus merged 1 commit into
masterfrom
mbaraniak/github-action-pinning

Conversation

@mbaraniak-exodus
Copy link
Copy Markdown

📝 Summary

This PR pins third-party GitHub Actions to full commit SHAs.
Internal ExodusMovement/... actions are out of scope for this campaign and are intentionally not locked in these changes.
This removes floating action references and reduces supply-chain risk by ensuring workflow execution uses reviewed, immutable upstream revisions instead of tags that can be moved.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 5, 2026

Size Change: 0 B

Total Size: 75.9 kB

ℹ️ View Unchanged
Filename Size
index.js 75.9 kB

compressed-size-action

Copy link
Copy Markdown

@ale-exo ale-exo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utACK

  • https://github.com/actions/checkout/releases/tag/v2.7.0
  • https://github.com/actions/setup-node/releases/tag/v1.4.6

@mbaraniak-exodus mbaraniak-exodus merged commit e0a8816 into master May 6, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants