Skip to content

[CI] Pin GitHub Actions to specific commit SHAs#27185

Merged
dschuff merged 1 commit into
emscripten-core:mainfrom
dschuff:pin-actions
Jun 25, 2026
Merged

[CI] Pin GitHub Actions to specific commit SHAs#27185
dschuff merged 1 commit into
emscripten-core:mainfrom
dschuff:pin-actions

Conversation

@dschuff

@dschuff dschuff commented Jun 25, 2026

Copy link
Copy Markdown
Member

Pin actions/checkout and setup-emsdk to specific commit SHAs to
ensure build reproducibility and security against upstream changes.

Pin actions/checkout and setup-emsdk to specific commit SHAs to
ensure build reproducibility and security against upstream changes.
@sbc100 sbc100 changed the title Pin GitHub Actions to specific commit SHAs [CI] Pin GitHub Actions to specific commit SHAs Jun 25, 2026

@sbc100 sbc100 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This one always seemed a little excessive then using standard actions like this but I guess its good policy

@dschuff

dschuff commented Jun 25, 2026

Copy link
Copy Markdown
Member Author

Yeah. I'm going to look into turning on dependabot too, so we should end up better off than where we started.

@dschuff dschuff merged commit 724d383 into emscripten-core:main Jun 25, 2026
39 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants