chore: Pin third-party GitHub Actions to full commit SHAs#71
Conversation
Original prompt from will.porter
|
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
Greptile SummaryThis PR replaces mutable version tags ( Confidence Score: 5/5Safe to merge — SHA pins are correct and verified against upstream releases. Only change is pinning GitHub Actions to verified commit SHAs. Both SHAs resolve to the expected versions. The sole finding is a P2 style nit about the version comment being No files require special attention. Important Files Changed
Reviews (1): Last reviewed commit: "Pin third-party GitHub Actions to full c..." | Re-trigger Greptile |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 | ||
| - name: Setup Node | ||
| uses: actions/setup-node@v6 | ||
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 |
There was a problem hiding this comment.
Imprecise version comment for pinned SHA
The SHA 48b55a0... resolves to actions/setup-node@v6.4.0, but the comment only says # v6. Using the full version tag in the comment (e.g., # v6.4.0) makes it much easier to audit which exact release is pinned and to know when a newer patch/minor is available. The same applies to every other setup-node reference in this file and in release.yml.
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 |
Third-Party Action SHA Age Report
|
file:///home/ubuntu/pin-actions/authkit-react-router_pr_body.md
Link to Devin session: https://app.devin.ai/sessions/add87be2227046f198fbac38a32e5358