Skip to content

Conversation

@rxbchen
Copy link
Contributor

@rxbchen rxbchen commented May 12, 2025

This is an automated PR to update actions in this repo. The operation should be no-op, as we are only switching out the version tag with the matching commit SHA.

To align with industry best practices, we are going to pin Github Actions to a specific commit SHA.

To read more about why pinning actions is recommended check here.

To ensure these Actions stay to-do-date, this PR also enables Dependabot automated updates. To read more about this configuration check here.

Please reach out if you have any questions. This PR will be merged in ~1 week.

@rxbchen rxbchen requested a review from a team as a code owner May 12, 2025 20:31
upgrade-umpire[bot]
upgrade-umpire bot previously approved these changes Jun 11, 2025
@upgrade-umpire upgrade-umpire bot dismissed their stale review June 11, 2025 19:54

An error occurred when attempting to merge this PR

@rxbchen
Copy link
Contributor Author

rxbchen commented Jun 11, 2025

@lizkenyon Sorry to ping you on this review as well. Just wanted to get your team's opinion on whether or not your team is alright with this change.

What this means is that the repo will get regular dependabot updates every week to bump the commit SHA of actions (if there are newer versions). If you don't want the toil that this brings, I can close the PR and add it to the exceptions.

Thanks 🙏

Copy link
Contributor

@lizkenyon lizkenyon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the slow review! We will take this on.

@lizkenyon lizkenyon merged commit 633b493 into main Jun 11, 2025
9 checks passed
@lizkenyon lizkenyon deleted the pin-actions-commit branch June 11, 2025 20:20
@rxbchen
Copy link
Contributor Author

rxbchen commented Jun 11, 2025

No worries! Just didn't want to add too much toil for your team!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants