Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build: pin GitHub Actions using hashes #400

Merged
merged 1 commit into from
May 22, 2024
Merged

Conversation

matijs
Copy link
Member

@matijs matijs commented May 22, 2024

Pin GitHub Actions using hashes to prevent tampering. Tags are added as comments and both will be updated by Dependabot in pull requests. Update actions to their latest versions.

Make explicit again that pnpm when run in CI is run with --frozen-lockfile.

Pin GitHub Actions using hashes to prevent tampering. Tags are added as
comments and both will be updated by Dependabot in pull requests.

Make explicit again that pnpm when run in CI is run with
`--frozen-lockfile`.
@matijs matijs requested review from Robbert and bddjong May 22, 2024 20:09
@matijs matijs enabled auto-merge (rebase) May 22, 2024 20:09
@matijs matijs merged commit acfc578 into main May 22, 2024
2 checks passed
@matijs matijs deleted the build/pin-github-actions branch May 22, 2024 20:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants