Skip to content

[9.x] Pin GitHub Actions to commit SHAs and add Dependabot config#816

Merged
duncanmcclean merged 1 commit into
9.xfrom
pin-github-actions-to-shas
May 14, 2026
Merged

[9.x] Pin GitHub Actions to commit SHAs and add Dependabot config#816
duncanmcclean merged 1 commit into
9.xfrom
pin-github-actions-to-shas

Conversation

@duncanmcclean
Copy link
Copy Markdown
Member

@duncanmcclean duncanmcclean commented May 14, 2026

All GitHub Actions are pinned to specific commit SHAs (with version comments) across every workflow file.

A .github/dependabot.yml is added to keep pinned action SHAs up to date automatically via weekly grouped PRs.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@duncanmcclean duncanmcclean changed the title [9.x] Pin GitHub Actions to commit SHAs [9.x] Pin GitHub Actions to commit SHAs and add Dependabot config May 14, 2026
@duncanmcclean duncanmcclean marked this pull request as ready for review May 14, 2026 08:27
@duncanmcclean duncanmcclean merged commit 5dea95f into 9.x May 14, 2026
16 checks passed
@duncanmcclean duncanmcclean deleted the pin-github-actions-to-shas branch May 14, 2026 08:27
@github-actions
Copy link
Copy Markdown

Released as part of v9.4.6.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant