From 947a24903a7745199c135361865ecfa2fed780b4 Mon Sep 17 00:00:00 2001 From: generalpawz Date: Sat, 26 Sep 2026 15:12:38 +0000 Subject: [PATCH 1/2] ci: pin actions in .github/workflows/ci.yml to commit SHAs Claude-Session: https://claude.ai/code/session_01V2HyuKe7QWf4WKxHdEJEjD --- .github/workflows/ci.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index e63ac50..10be045 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -11,10 +11,10 @@ jobs: gate: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 - - uses: dtolnay/rust-toolchain@stable + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable with: toolchain: 1.88.0 components: rustfmt, clippy - - uses: Swatinem/rust-cache@v2 + - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 - run: bash scripts/gate.sh From 7a7033eaaf0bb307db7d26629ccc28d12db7c378 Mon Sep 17 00:00:00 2001 From: generalpawz Date: Sat, 26 Sep 2026 15:12:39 +0000 Subject: [PATCH 2/2] ci: keep action pins current with Dependabot Claude-Session: https://claude.ai/code/session_01V2HyuKe7QWf4WKxHdEJEjD --- .github/dependabot.yml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..be78a9c --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,14 @@ +# Workflows pin every action to a full commit SHA (a moved tag cannot change +# what runs). Dependabot keeps those pins current: it proposes the new SHA and +# rewrites the version comment beside it, one grouped PR a week. +version: 2 +updates: + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + groups: + github-actions: + patterns: ["*"] + commit-message: + prefix: ci