Skip to content

Pin actions to specific SHA#752

Closed
r7sy wants to merge 1 commit into
jaraco:mainfrom
r7sy:main
Closed

Pin actions to specific SHA#752
r7sy wants to merge 1 commit into
jaraco:mainfrom
r7sy:main

Conversation

@r7sy
Copy link
Copy Markdown

@r7sy r7sy commented Apr 28, 2026

Improve OSSF scorecard of this project by pinning actions to specific SHAs and avoiding mutable tags. Dependabot is still able to upgrade actions and will update comments.

@r7sy
Copy link
Copy Markdown
Author

r7sy commented May 5, 2026

Closing since this is covered by #749

I opened this new one because I couldn't find my PR due to the github incident.

@r7sy r7sy closed this May 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant