Skip to content

Pin GitHub Actions#73

Merged
bjosv merged 1 commit into
valkey-io:mainfrom
SuperQ:superq/pin_actions
Feb 4, 2026
Merged

Pin GitHub Actions#73
bjosv merged 1 commit into
valkey-io:mainfrom
SuperQ:superq/pin_actions

Conversation

@SuperQ
Copy link
Copy Markdown
Contributor

@SuperQ SuperQ commented Feb 2, 2026

It is recommended for supply chains security to ping GitHub Actions to specific commit hashes in order to avoid stealth updates. Apply the latest commit hash for each of the used actions.

  • Update all GitHub actions to latest.
  • Enable monthly dependabot config to keep actions up-to-date.

Copy link
Copy Markdown
Collaborator

@bjosv bjosv left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great! This will make the OpenSSF-people happy as well

Comment thread .github/workflows/auto_update.yml Outdated
Comment thread .github/dependabot.yml
It is recommended for supply chains security to ping GitHub Actions
to specific commit hashes in order to avoid stealth updates. Apply
the latest commit hash for each of the used actions.
* Update all GitHub actions to latest.
* Enable monthly dependabot config to keep actions up-to-date.

Signed-off-by: SuperQ <superq@gmail.com>
@SuperQ SuperQ force-pushed the superq/pin_actions branch from 98ea16d to 4d0e847 Compare February 2, 2026 09:44
Copy link
Copy Markdown
Collaborator

@jdheyburn jdheyburn left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@bjosv bjosv merged commit a00dfe2 into valkey-io:main Feb 4, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants