Skip to content

ci: pin every action to a commit SHA; Dependabot for action pins - #6

Merged
GeneralPawz merged 2 commits into
mainfrom
ci/harden-actions
Sep 26, 2026
Merged

GeneralPawz merged 2 commits into
mainfrom
ci/harden-actions

Conversation

@GeneralPawz

@GeneralPawz GeneralPawz commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Pins every action to the commit its tag points at today, with the precise version as a comment. No version changes: behaviour is identical, but a moved tag can no longer change what runs.
  • Adds .github/dependabot.yml: one grouped weekly github-actions PR keeps the pins and comments current.

Pins

  • .github/workflows/ci.yml: actions/checkout@v7 -> 3d3c42e5aac5 (v7.0.1)
  • .github/workflows/ci.yml: dtolnay/rust-toolchain@1.85.0 -> 3230091d7ef9 (1.85.0)

After merge

Enable Settings → Actions → General → "Require actions to be pinned to a full-length commit SHA" (already on for every compliant repo in openbimrs/axiolid/axioval).

@GeneralPawz
GeneralPawz merged commit dfe72aa into main Sep 26, 2026
3 checks passed
@GeneralPawz
GeneralPawz deleted the ci/harden-actions branch September 26, 2026 15:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant