Skip to content

Conversation

@rwaight
Copy link

@rwaight rwaight commented Jan 7, 2025

The purpose of this PR is to improve the baseline security for using GitHub Actions with the docs-builder; mainly to improve user awareness as they use this elastic/docs-builder repo to deploy documentation using GitHub Actions.

This PR pins the GitHub actions to the commit SHA, with a comment including the version.

This also adds notes to the workflow with a link to the action in the GitHub Marketplace.

This is related to #146 and elastic/docs-builder-example#12

@Mpdreamz
Copy link
Member

Mpdreamz commented Jan 8, 2025

As discussed here #146 (comment) we are good to depend on tags for GitHub and Elastic published actions.

@Mpdreamz Mpdreamz closed this Jan 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants