Skip to content

chore: use pinned dependencies for github-actions #13140

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

mmorel-35
Copy link
Contributor

@mmorel-35 mmorel-35 commented Aug 8, 2025

What I did

Scorecard asks for dependencies to be pinned (github-actions as Docker images), this focus on github-actions.
It provides the commits number to the used actions.
It also updates dependabot so both commit and semver are checked weekly for update.

OpenSSF Scorecard

Related issue

(not mandatory) A picture of a cute animal, if possible in relation to what you did

@mmorel-35 mmorel-35 requested a review from a team as a code owner August 8, 2025 12:57
@mmorel-35 mmorel-35 requested review from ndeloof and glours August 8, 2025 12:57
@mmorel-35 mmorel-35 force-pushed the pin-github-actions-versions branch from 2ccc3de to a313715 Compare August 8, 2025 12:57
@mmorel-35 mmorel-35 force-pushed the pin-github-actions-versions branch from a313715 to e7dca0a Compare August 8, 2025 13:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant