Skip to content

ci: pin all actions to full commit SHAs#89

Merged
sr-murthy merged 1 commit into
mainfrom
pin-actions-to-commit-shas
Apr 16, 2026
Merged

ci: pin all actions to full commit SHAs#89
sr-murthy merged 1 commit into
mainfrom
pin-actions-to-commit-shas

Conversation

@sr-murthy
Copy link
Copy Markdown
Member

@sr-murthy sr-murthy commented Apr 16, 2026

Pin all workflow actions to full commit SHAs - to support more secure workflow permission settings, screenshot below of intended settings to be applied before the merge:

Screenshot 2026-04-16 at 08 16 45

For clarity this is a table summarising the actions and the release versions/tags corresponding to the first 8 commit SHAs.

Action Release Version/Tag Commit SHA (first 8 chars.)
checkout v6 de0fac2e
setup-python v6 a309ff8b
upload-artifact v6 b7c566a7
configure-aws-credentials v6 ec61189d
codecov-action v6 57e3a136

@sr-murthy sr-murthy self-assigned this Apr 16, 2026
@sr-murthy sr-murthy added the ci Continuous integration label Apr 16, 2026
@sr-murthy sr-murthy linked an issue Apr 16, 2026 that may be closed by this pull request
@codecov
Copy link
Copy Markdown

codecov Bot commented Apr 16, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@sr-murthy sr-murthy force-pushed the pin-actions-to-commit-shas branch from a999dbe to 6be6d05 Compare April 16, 2026 12:38
@alasdairwilson
Copy link
Copy Markdown
Member

alasdairwilson commented Apr 16, 2026

LGTM, I'll leave you to merge it when you are ready

@sr-murthy sr-murthy merged commit 01b941e into main Apr 16, 2026
13 checks passed
@sr-murthy sr-murthy deleted the pin-actions-to-commit-shas branch April 16, 2026 13:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Continuous integration

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pin non first-party GitHub Actions

2 participants