Skip to content

Conversation

SMoraisAnsys
Copy link
Contributor

@SMoraisAnsys SMoraisAnsys commented Aug 25, 2025

I just discovered that GitHub has (now) a setting for enforcing the use of pinned actions. The drawbacks with enabling this setting are:

  • additional maintenance as the number of dependabot PR will increase, but the pros are totally worth it;
  • our ansys/actions will have to be pinned as the rest of the actions - this could be controversial for some developers that believe they can use our actions without checking the changes.

Reference: https://docs.github.com/en/actions/reference/security/secure-use#using-third-party-actions

The option is on the bottom right of the screen
image

@github-actions github-actions bot added documentation Improvements or additions to documentation enhancement New features or code improvements labels Aug 25, 2025
@SMoraisAnsys
Copy link
Contributor Author

This PR is related to #590 be could be merged without it. I forgot about #590 and will take some time to work on it soon.

Copy link
Member

@RobPasMue RobPasMue left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pretty interesting!

@RobPasMue
Copy link
Member

RobPasMue commented Aug 25, 2025

BTW - I would add the link to the official docs if possible as well as part of your description

@SMoraisAnsys SMoraisAnsys self-assigned this Aug 27, 2025
@SMoraisAnsys SMoraisAnsys marked this pull request as draft August 27, 2025 09:14
@SMoraisAnsys
Copy link
Contributor Author

SMoraisAnsys commented Aug 27, 2025

Convertion to draft until the issue of having the whole chain of action being pinned is not resolved from our ansys actions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation enhancement New features or code improvements
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants