Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: Pin actions to hashes TDE-934 #332

Merged
merged 1 commit into from
Nov 27, 2023
Merged

feat: Pin actions to hashes TDE-934 #332

merged 1 commit into from
Nov 27, 2023

Conversation

l0b0
Copy link
Contributor

@l0b0 l0b0 commented Nov 16, 2023

Done with pin-github-action https://github.com/mheap/pin-github-action 1.8.0 using npx pin-github-action .github/workflows/*.yml.

Dependabot should support updating in the same fashion dependabot/dependabot-core#8277 (comment).

Had to export GH_ADMIN_TOKEN=github_pat_… using a fine-grained personal access tokens with no extra access to work around rate limiting and to be able to work in private repos
mheap/pin-github-action#73.

Done with pin-github-action <https://github.com/mheap/pin-github-action>
1.8.0 using `npx pin-github-action .github/workflows/*.yml`.

Dependabot should support updating in the same fashion
<dependabot/dependabot-core#8277 (comment)>.

Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal
access tokens with no extra access to work around rate limiting *and* to be
able to work in private repos
<mheap/pin-github-action#73>.
@l0b0 l0b0 requested a review from a team as a code owner November 16, 2023 01:13
@l0b0 l0b0 changed the title feat: Pin actions to hashes feat: Pin actions to hashes TDE-934 Nov 16, 2023
@l0b0 l0b0 added this pull request to the merge queue Nov 27, 2023
Merged via the queue into master with commit d9451ea Nov 27, 2023
2 checks passed
@l0b0 l0b0 deleted the feat/pin-actions branch November 27, 2023 21:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

2 participants