Skip to content
This repository has been archived by the owner on Nov 15, 2023. It is now read-only.

pin gha versions #12100

Merged
merged 1 commit into from
Aug 25, 2022
Merged

pin gha versions #12100

merged 1 commit into from
Aug 25, 2022

Conversation

sergejparity
Copy link
Contributor

In order to improve our security posture with GitHub Actions usage. I've made a version pinning ether to commit hash or to specific version.

Related issues and policy:
https://github.com/paritytech/ci_cd/issues/464
https://github.com/paritytech/ci_cd/wiki/Policies-and-regulations:-GitHub-Actions-usage-policies

@sergejparity sergejparity added A2-insubstantial Pull request requires no code review (e.g., a sub-repository hash update). B0-silent Changes should not be mentioned in any release notes C1-low PR touches the given topic and has a low impact on builders. E3-dependencies labels Aug 24, 2022
@sergejparity sergejparity requested a review from a team as a code owner August 24, 2022 13:34
@paritytech-ci paritytech-ci requested a review from a team August 24, 2022 14:18
Copy link
Contributor

@gilescope gilescope left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@sergejparity sergejparity merged commit 2b54771 into master Aug 25, 2022
@sergejparity sergejparity deleted the sk-pin-gha-versions branch August 25, 2022 14:52
ark0f pushed a commit to gear-tech/substrate that referenced this pull request Feb 27, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
A2-insubstantial Pull request requires no code review (e.g., a sub-repository hash update). B0-silent Changes should not be mentioned in any release notes C1-low PR touches the given topic and has a low impact on builders.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants