Skip to content

Conversation

@billnapier
Copy link
Contributor

This will look at all workflow files and look at:

uses: org/repo@v5

and encourage users to instead pin those to git commits.

This will look at all workflow files and look at:

```
uses: org/repo@v5
```

and encourage users to instead pin those to git commits.
@github-actions
Copy link

github-actions bot commented Mar 31, 2025

PR Preview Action v1.6.0
Preview removed because the pull request was closed.
2025-03-31 21:03 UTC

@billnapier billnapier changed the title Add semgrep tests for pinned actions. Add semgrep checks for pinned actions. Mar 31, 2025
@billnapier billnapier marked this pull request as ready for review March 31, 2025 20:30
@billnapier billnapier requested a review from a team March 31, 2025 20:31
@billnapier billnapier merged commit cf58e83 into master Mar 31, 2025
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants