Skip to content

ci: pin every action to a commit SHA - #27

Merged
aledbf merged 1 commit into
mainfrom
pin-actions-sha
Oct 3, 2026
Merged

aledbf merged 1 commit into
mainfrom
pin-actions-sha

Conversation

@aledbf

@aledbf aledbf commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Pins every uses: to the commit SHA its tag points at today, with the tag as a comment. Needed before the org enables sha_pinning_required, which fails any workflow that references an action by tag.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

The org is turning on sha_pinning_required: a tag can be moved to
code nobody reviewed, a SHA cannot. The tag stays as a comment so
Dependabot and a reader still see the version.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
@aledbf
aledbf merged commit dc2c898 into main Oct 3, 2026
14 checks passed
@aledbf
aledbf deleted the pin-actions-sha branch October 3, 2026 13:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant