Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: Pin actions to hashes TDE-934 #89

Merged
merged 1 commit into from
Dec 15, 2023
Merged

feat: Pin actions to hashes TDE-934 #89

merged 1 commit into from
Dec 15, 2023

Conversation

l0b0
Copy link
Contributor

@l0b0 l0b0 commented Nov 16, 2023

Done with pin-github-action https://github.com/mheap/pin-github-action 1.8.0 using npx pin-github-action .github/workflows/*.yml.

Dependabot should support updating in the same fashion dependabot/dependabot-core#8277 (comment).

Had to export GH_ADMIN_TOKEN=github_pat_… using a fine-grained personal access tokens with no extra access to work around rate limiting and to be able to work in private repos
mheap/pin-github-action#73.

Done with pin-github-action <https://github.com/mheap/pin-github-action>
1.8.0 using `npx pin-github-action .github/workflows/*.yml`.

Dependabot should support updating in the same fashion
<dependabot/dependabot-core#8277 (comment)>.

Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal
access tokens with no extra access to work around rate limiting *and* to be
able to work in private repos
<mheap/pin-github-action#73>.
@l0b0 l0b0 requested a review from blacha November 16, 2023 01:50
@l0b0 l0b0 enabled auto-merge November 16, 2023 01:50
@l0b0 l0b0 disabled auto-merge December 15, 2023 00:45
@l0b0 l0b0 added this pull request to the merge queue Dec 15, 2023
Merged via the queue into master with commit 6c15b9e Dec 15, 2023
1 check passed
@l0b0 l0b0 deleted the feat/pin-actions branch December 15, 2023 00:45
github-merge-queue bot pushed a commit that referenced this pull request Dec 15, 2023
🤖 I have created a release *beep* *boop*
---


##
[0.2.0](v0.1.0...v0.2.0)
(2023-12-15)


### Features

* Pin actions to hashes TDE-934
([#89](#89))
([6c15b9e](6c15b9e))


### Bug Fixes

* Use the same prefix for all Dependabot commits
([#61](#61))
([e915396](e915396))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

3 participants