Skip to content

ci: pin third-party actions to commit-hash#704

Merged
Uzlopak merged 1 commit into
mainfrom
ci/tp-actions
Jun 17, 2025
Merged

ci: pin third-party actions to commit-hash#704
Uzlopak merged 1 commit into
mainfrom
ci/tp-actions

Conversation

@Fdawgs
Copy link
Copy Markdown
Member

@Fdawgs Fdawgs commented Jun 16, 2025

Closes https://github.com/fastify/github-action-merge-dependabot/security/code-scanning/5 and 3 other code scanning alerts.

Most first-party actions now use https://github.com/actions/publish-immutable-action, which negates the need for commit hashes, but this is not available for third-party actions yet.

@github-actions
Copy link
Copy Markdown

No linked issues found. Please add the corresponding issues in the pull request description.
Use GitHub automation to close the issue when a PR is merged

@Fdawgs Fdawgs requested a review from Eomm June 16, 2025 06:33
Copy link
Copy Markdown
Contributor

@Uzlopak Uzlopak left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Uzlopak Uzlopak merged commit 446d946 into main Jun 17, 2025
5 of 8 checks passed
@Uzlopak Uzlopak deleted the ci/tp-actions branch June 17, 2025 11:21
@github-actions github-actions Bot mentioned this pull request Jun 18, 2025
@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 1, 2026

This pull request has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@github-actions github-actions Bot locked as resolved and limited conversation to collaborators May 1, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants