Skip to content

Comments

ci(.github): pin actions to commit-hash; set permissions at job level#422

Merged
Fdawgs merged 2 commits intomainfrom
ci/pin
Mar 21, 2025
Merged

ci(.github): pin actions to commit-hash; set permissions at job level#422
Fdawgs merged 2 commits intomainfrom
ci/pin

Conversation

@Fdawgs
Copy link
Owner

@Fdawgs Fdawgs commented Mar 21, 2025

Also swap out unsafe automerge for fastify/github-action-merge-dependabot.

After what has been happening with tj-actions/changed-files over the past week this is probably a sensible idea.

See related blog post by rafaelgss about pinning to the commit-hash.

Checklist

@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@Fdawgs Fdawgs merged commit 34826e1 into main Mar 21, 2025
21 checks passed
@Fdawgs Fdawgs deleted the ci/pin branch March 21, 2025 15:13
@github-actions
Copy link
Contributor

This pull request has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Nov 16, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant