Skip to content

Conversation

@pnacht
Copy link
Contributor

@pnacht pnacht commented Sep 4, 2023

Fixes #818.

This PR hash-pins all GitHub Actions to ensure their behavior is as expected, protecting the project from supply-chain attacks.

These hashes (and version comments) will be kept up-to-date by dependabot.

ci-release.yml uses crazy-max/ghaction-import-gpg. It was at v3, but the Action is now at v5. The only breaking change was to one argument name, so I've taken the liberty of making that bump.

Signed-off-by: Pedro Kaj Kjellerup Nacht <[email protected]>
Signed-off-by: Pedro Kaj Kjellerup Nacht <[email protected]>
@pnacht
Copy link
Contributor Author

pnacht commented Nov 17, 2023

Let me know if this is something the project is interested in. If not, feel free to close!

@normanmaurer normanmaurer force-pushed the main branch 8 times, most recently from 3d64a79 to 4c63e52 Compare May 20, 2025 13:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Hash-pin workflow GitHub Actions

1 participant