ci: pin GitHub Actions to commit SHAs in release workflow#1439
ci: pin GitHub Actions to commit SHAs in release workflow#1439matiasinsaurralde wants to merge 1 commit into
Conversation
Signed-off-by: Matías Insaurralde <matias@insaurral.de>
|
We require contributors to sign our Contributor License Agreement, and we don't have @matiasinsaurralde on file. You can sign our CLA at https://e2b.dev/docs/cla . Once you've signed, post a comment here that says '@cla-bot check' |
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
|
|
@cla-bot check |
|
The cla-bot has been summoned, and re-checked this pull request! |
|
Think it's okay to keep it as-is - any objections @jakubno? |
Summary
release.ymlto full commit SHAs to prevent supply-chain attacks via tag mutationactions/checkout,wistia/parse-tool-versions,pnpm/action-setup,actions/setup-node,rtCamp/action-slack-notify