Skip to content

Immutable ReleasesΒ #521

@CalvinRodo

Description

@CalvinRodo

Enabling this will make it easier to use this action in a secure way, with mutable tags I need to either fork this action or pin to a Git SHA to ensure that I am using a known version of this action, with an immutable release I can pin to the tag and be confident the code won't be maliciously modified due to a compromise of this repo.

https://docs.github.com/en/actions/how-tos/create-and-publish-actions/using-immutable-releases-and-tags-to-manage-your-actions-releases

It also makes it easier to understand what version we are using in workflows as we can view the version number instead of a sha

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestgithub_actionsPull requests that update GitHub Actions codereleaseTags for an updated version

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions