Skip to content

fix(github-actions): pin versions to sha#5116

Merged
PatrickGoRaft merged 1 commit intomasterfrom
5528-pin-github-actions-to-sha
Apr 30, 2026
Merged

fix(github-actions): pin versions to sha#5116
PatrickGoRaft merged 1 commit intomasterfrom
5528-pin-github-actions-to-sha

Conversation

@billhimmelsbach
Copy link
Copy Markdown
Contributor

@billhimmelsbach billhimmelsbach commented Apr 29, 2026

Due to some recent supply chain attacks, Lamin would prefer if we locked the github actions to SHAs instead of just the version number. I used the same script that cf.gov used over here, thanks @chosak!

Changes

  • Instead of using a version number, locks github actions to SHAs

Testing

  1. Do the github actions still work? Yes!
  2. Do the tests still pass? Yes!

@billhimmelsbach billhimmelsbach marked this pull request as ready for review April 29, 2026 16:17
Copy link
Copy Markdown
Contributor

@PatrickGoRaft PatrickGoRaft left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@PatrickGoRaft PatrickGoRaft merged commit 027c563 into master Apr 30, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants