Pin third-party actions to commit SHAs#61
Conversation
techncl
left a comment
There was a problem hiding this comment.
Just 2 questions:
- these are very old versions, should we update them now, or wait for dependabot?
- Line 26 just has
#v2without any decimals; is that valid?
By the way, in case you were wondering, I added branch protection on this repo
|
|
|
I'm not sure; this is a Java library so maybe someone, somewhere is using it. |
This PR pins third-party GitHub Actions to full commit SHAs for supply-chain security.
This has been done automatically by pinact. When reviewing please confirm that the SHAs are correct, zizmor will alert if not.
As a maintainer, please merge this PR once approved.