Skip to content

Commit 4ae8a30

Browse files
authored
Use commit hash for dependabot-auto-approve action (#212)
## Summary - Replace version tag `@v1` with commit hash for `frequenz-floss/dependabot-auto-approve` action - Improves security and reproducibility by pinning to exact commit
2 parents 9c4c76b + d209839 commit 4ae8a30

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

.github/workflows/auto-dependabot.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ jobs:
1010
runs-on: ubuntu-latest
1111
if: github.actor == 'dependabot[bot]'
1212
steps:
13-
- uses: frequenz-floss/dependabot-auto-approve@v1
13+
- uses: frequenz-floss/dependabot-auto-approve@005e52004f5d5c6af2f81b89ec25e5cf6f3dfd77 # v1.3.0
1414
with:
1515
dependency-type: 'all'
1616
auto-merge: 'true'

0 commit comments

Comments
 (0)