Skip to content

Conversation

@jonasbn
Copy link
Owner

@jonasbn jonasbn commented Jan 31, 2026

This PR updates GitHub Actions to their latest stable releases and ensures they are pinned to specific commit SHAs for security.

Changes

Updated Actions:

  • step-security/harden-runner: v2.14.0 → v2.14.1

    • SHA: 20cf305e3f713f
  • github/codeql-action/* (init, autobuild, analyze, upload-sarif): v4.31.11 → v4.32.0

    • SHA: 19b2f06b20883b

Files Updated:

  • ✅ check-spelling.yml
  • ✅ codeql.yml
  • ✅ dependency-review.yml
  • ✅ go-build.yml
  • ✅ go-releaser.yml
  • ✅ markdownlint.yml
  • ✅ scorecard.yml

Security & Maintenance

All actions are pinned to specific commit SHAs with human-readable version comments (e.g., # v2.14.1) to allow Dependabot to automatically manage future updates while maintaining security through SHA pinning.

Verification

All actions have been verified against their official GitHub repositories to ensure the latest stable releases are used.

- Update step-security/harden-runner from v2.14.0 to v2.14.1
- Update github/codeql-action/* from v4.31.11 to v4.32.0

All actions are now pinned to commit SHAs with version comments for
Dependabot compatibility.
@coveralls
Copy link

Pull Request Test Coverage Report for Build 21546482780

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 73.089%

Totals Coverage Status
Change from base Build 21460156191: 0.0%
Covered Lines: 239
Relevant Lines: 327

💛 - Coveralls

@jonasbn jonasbn merged commit ead07e9 into main Jan 31, 2026
8 checks passed
@jonasbn jonasbn deleted the copilot/pin-actions-to-latest-releases branch January 31, 2026 15:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants