Skip to content

chore: pin third-party GitHub Actions to SHAs + enable Dependabot#246

Merged
chubes4 merged 1 commit into
mainfrom
chore/pin-and-enable-dependabot
Jun 1, 2026
Merged

chore: pin third-party GitHub Actions to SHAs + enable Dependabot#246
chubes4 merged 1 commit into
mainfrom
chore/pin-and-enable-dependabot

Conversation

@mahangu
Copy link
Copy Markdown

@mahangu mahangu commented May 31, 2026

Two-in-one hardening:

  1. Pin third-party GitHub Actions in this repo to commit SHAs (tag preserved as trailing comment).
  2. Add Dependabot github-actions config (weekly, grouped into actions-minor-patch and actions-major, with cooldown).

Tracking: DEVPROD-1072.

Pin partial: 1/2 refs resolved; remainder use moving branch refs and need manual pinning.

Hardens against supply-chain risk on mutable tags. Dependabot keeps
the pinned SHAs fresh weekly, with major bumps held under cooldown.

Tracking: DEVPROD-1072
@mahangu mahangu requested a review from chubes4 June 1, 2026 01:46
@mahangu mahangu self-assigned this Jun 1, 2026
@chubes4 chubes4 merged commit 12cd7e5 into main Jun 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants