Skip to content
This repository has been archived by the owner on Jan 18, 2024. It is now read-only.

CI: pin GitHub Actions workflows #106

Closed
wants to merge 1 commit into from

Conversation

ErikSchierboom
Copy link
Member

This PR updates GitHub Actions workflows to a specific version.
This ensures that the workflow will always run the same code, which makes your build stable.
It will also prevent a potential security issue where a tag could be replaced by a malicious commit without consumers being aware of it.

The PR updates each non-SHA based workflow reference with the SHA of the referenced version/tag, so the current behavior should not change.

See https://exercism.org/docs/building/github/gha-best-practices#h-pin-actions-to-shas for more information.

@ErikSchierboom ErikSchierboom added the x:size/tiny Tiny amount of work label Nov 14, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
x:size/tiny Tiny amount of work
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant