Skip to content

ci: note why SHA-pin enforcement is off at the OSV pin - #109

Merged
kellenmurphy merged 1 commit into
mainfrom
ci/osv-sha-pin-note
Jun 7, 2026
Merged

ci: note why SHA-pin enforcement is off at the OSV pin#109
kellenmurphy merged 1 commit into
mainfrom
ci/osv-sha-pin-note

Conversation

@kellenmurphy

@kellenmurphy kellenmurphy commented Jun 7, 2026

Copy link
Copy Markdown
Owner

No description provided.

The "Require actions pinned to a full-length commit SHA" repo setting is
disabled because osv-scanner-action v2.3.8's reusable workflow ships an
unpinned actions/download-artifact, which GitHub enforces recursively and
fails this job at startup. Fixed upstream on main (f6fb127), unreleased.
Re-enable once Dependabot bumps this pin past the next release.

ci-only change (release-please no-op).
@kellenmurphy
kellenmurphy enabled auto-merge June 7, 2026 20:10
@codecov

codecov Bot commented Jun 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@kellenmurphy
kellenmurphy merged commit 42091dc into main Jun 7, 2026
12 checks passed
@kellenmurphy
kellenmurphy deleted the ci/osv-sha-pin-note branch June 15, 2026 17:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant