chore: Pin third-party GitHub Actions to full commit SHAs#73
chore: Pin third-party GitHub Actions to full commit SHAs#73gjtorikian merged 3 commits intomainfrom
Conversation
Original prompt from will.porter
|
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
Co-Authored-By: will.porter <will.porter@workos.com>
Greptile SummaryThis PR replaces all floating version tags (e.g. Confidence Score: 5/5Safe to merge — purely a security hardening change with no functional impact. All changes are SHA-pinning of well-known, widely-used GitHub Actions. No logic is altered, comments preserve the human-readable version labels, and the change is internally consistent across all three workflow files. No files require special attention. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Push / PR event] --> B{Workflow triggered}
B --> C[ci.yml - CI]
B --> D[release-please.yml - Release Please]
D --> E[release.yml - Publish to NPM]
C --> C1["actions/checkout\n@34e1148... #v4"]
C --> C2["pnpm/action-setup\n@b906aff... #v4"]
C --> C3["actions/setup-node\n@49933ea... #v4"]
D --> D1["actions/create-github-app-token\n@fee1f7d... #v2"]
D --> D2["googleapis/release-please-action\n@5c625bf... #v4"]
E --> E1["actions/checkout\n@34e1148... #v4"]
E --> E2["pnpm/action-setup\n@b906aff... #v4"]
E --> E3["actions/setup-node\n@49933ea... #v4"]
Reviews (2): Last reviewed commit: "Fix formatting in workflow files" | Re-trigger Greptile |
Third-Party Action SHA Age Report
|
Co-Authored-By: will.porter <will.porter@workos.com>
file:///home/ubuntu/pin-actions/authkit-tanstack-start_pr_body.md
Link to Devin session: https://app.devin.ai/sessions/add87be2227046f198fbac38a32e5358