Skip to content

Pin GitHub Actions to commit SHAs and add Dependabot config#130

Merged
duncanmcclean merged 1 commit into
2.xfrom
pin-github-actions-to-shas
May 14, 2026
Merged

Pin GitHub Actions to commit SHAs and add Dependabot config#130
duncanmcclean merged 1 commit into
2.xfrom
pin-github-actions-to-shas

Conversation

@duncanmcclean
Copy link
Copy Markdown
Member

@duncanmcclean duncanmcclean commented May 14, 2026

All GitHub Actions are pinned to specific commit SHAs (with version comments) across every workflow file.

A .github/dependabot.yml is added to keep pinned action SHAs up to date automatically via weekly grouped PRs.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@duncanmcclean duncanmcclean marked this pull request as ready for review May 14, 2026 08:41
@duncanmcclean duncanmcclean merged commit 36b5016 into 2.x May 14, 2026
12 checks passed
@duncanmcclean duncanmcclean deleted the pin-github-actions-to-shas branch May 14, 2026 08:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant