Skip to content

Hash pin GitHub Actions#640

Open
hugovk wants to merge 2 commits into
jazzband:masterfrom
hugovk-test-org:hash-pin-gha
Open

Hash pin GitHub Actions#640
hugovk wants to merge 2 commits into
jazzband:masterfrom
hugovk-test-org:hash-pin-gha

Conversation

@hugovk
Copy link
Copy Markdown
Member

@hugovk hugovk commented Apr 24, 2026

Yet another compromise via unpinned GitHub Actions: https://socket.dev/blog/bitwarden-cli-compromised

Let's hash-pin GHA.

Done via uvx gha-update.

We can add Renovate or Dependabot later to update these once a month or so, but that can wait for #636 when we get admin access to enable those.

@hugovk hugovk added the changelog: skip Exclude PR from release draft label Apr 24, 2026
@codecov
Copy link
Copy Markdown

codecov Bot commented Apr 24, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.14%. Comparing base (564619d) to head (74282ac).

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #640   +/-   ##
=======================================
  Coverage   93.14%   93.14%           
=======================================
  Files          29       29           
  Lines        3226     3226           
=======================================
  Hits         3005     3005           
  Misses        221      221           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@hugovk
Copy link
Copy Markdown
Member Author

hugovk commented Apr 28, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

changelog: skip Exclude PR from release draft

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant