Skip to content

Commit f866deb

Browse files
fix(security): autofix 3rd party Github Actions should be pinned (#20)
Co-authored-by: aikido-autofix[bot] <119856028+aikido-autofix[bot]@users.noreply.github.com>
1 parent 6a2ef44 commit f866deb

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

.github/workflows/release.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ jobs:
3131
echo "Tag is on main branch, proceeding with release"
3232
3333
- name: Setup pnpm
34-
uses: pnpm/action-setup@v5
34+
uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
3535

3636
- name: Setup Node
3737
uses: actions/setup-node@v6
@@ -193,7 +193,7 @@ jobs:
193193
# OIDC trusted publishing (id-token: write) enables automatic provenance generation
194194

195195
- name: Create GitHub Release
196-
uses: softprops/action-gh-release@v3
196+
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0
197197
with:
198198
body_path: release_notes.md
199199
draft: false

0 commit comments

Comments
 (0)