Skip to content
This repository has been archived by the owner on Sep 14, 2023. It is now read-only.

Pin GHA versions and add dependabot #189

Merged
merged 1 commit into from
Aug 24, 2022
Merged

Conversation

sergejparity
Copy link
Contributor

In order to improve our security posture with GitHub Actions usage. I've made a version pinning ether to commit hash or to specific version.
Additionally added dependabot to track GHA version changes.
Related issues and policy:
https://github.com/paritytech/ci_cd/issues/114
https://github.com/paritytech/ci_cd/issues/464
https://github.com/paritytech/ci_cd/wiki/Policies-and-regulations:-GitHub-Actions-usage-policies

@sergejparity sergejparity merged commit 87cb38f into main Aug 24, 2022
@sergejparity sergejparity deleted the sk-pin-gha-version branch August 24, 2022 22:04
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants