You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ci(workflows): pin GitHub Actions dependencies to commit SHAs
Pin all third-party GitHub Actions to their full commit SHA
instead of mutable version tags. This is a supply-chain security
best practice that prevents tag-mutation attacks.
Changed files: build.yml, playwright.yml, pypi-publish.yml, release-image.yml
Total actions pinned: 17
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
0 commit comments