Skip to content

Commit f4f5a8a

Browse files
JeanMecheAndrewKushnir
authored andcommitted
ci: pin create-pull-request version to sha (angular#63409)
This is a new security requirement to prevent dependency compromission. PR Close angular#63409
1 parent a43057c commit f4f5a8a

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

.github/workflows/update-cdk-apis-and-cli-help.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ jobs:
3737
env:
3838
ANGULAR_CDK_BUILDS_READONLY_GITHUB_TOKEN: ${{ secrets.ANGULAR_CDK_BUILDS_READONLY_GITHUB_TOKEN }}
3939
- name: Create a PR CDK apis (if necessary)
40-
uses: peter-evans/create-pull-request@v7.0.8 # v7.0.8
40+
uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e # v7.0.8
4141
with:
4242
token: ${{ secrets.ANGULAR_ROBOT_ACCESS_TOKEN }}
4343
push-to-fork: 'angular-robot/angular'
@@ -66,7 +66,7 @@ jobs:
6666
env:
6767
ANGULAR_CLI_BUILDS_READONLY_GITHUB_TOKEN: ${{ secrets.ANGULAR_CLI_BUILDS_READONLY_GITHUB_TOKEN }}
6868
- name: Create a PR CLI help (if necessary)
69-
uses: peter-evans/create-pull-request@v7.0.8 # v7.0.8
69+
uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e # v7.0.8
7070
with:
7171
token: ${{ secrets.ANGULAR_ROBOT_ACCESS_TOKEN }}
7272
push-to-fork: 'angular-robot/angular'

0 commit comments

Comments
 (0)