Pin GitHub Actions to specific SHAs (13 actions in 6 files) #93
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
📌 Pin GitHub Actions to Specific SHAs
This PR updates GitHub Actions references from tags/branches to specific commit SHAs for improved security and reproducibility.
📊 Summary
📝 Changes by file
.github/workflows/changelog-check.yamlactions/checkout@v4→actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4miniscruff/changie-action@v2→miniscruff/changie-action@6dcc2533cac0495148ed4046c438487e4dceaa23 # miniscruff/changie-action@v2.github/workflows/create-release-pr.yamlactions/checkout@v4→actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4miniscruff/changie-action@v2→miniscruff/changie-action@6dcc2533cac0495148ed4046c438487e4dceaa23 # miniscruff/changie-action@v2miniscruff/changie-action@v2→miniscruff/changie-action@6dcc2533cac0495148ed4046c438487e4dceaa23 # miniscruff/changie-action@v2miniscruff/changie-action@v2→miniscruff/changie-action@6dcc2533cac0495148ed4046c438487e4dceaa23 # miniscruff/changie-action@v2peter-evans/create-pull-request@v4→peter-evans/create-pull-request@38e0b6e68b4c852a5500a94740f0e535e0d7ba54 # peter-evans/create-pull-request@v4.github/workflows/publish-test.yamlactions/checkout@v3→actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # actions/checkout@v3pypa/gh-action-pypi-publish@release/v1→pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # pypa/gh-action-pypi-publish@release/v1.github/workflows/publish.yamlactions/checkout@v4→actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4pypa/gh-action-pypi-publish@release/v1→pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # pypa/gh-action-pypi-publish@release/v1.github/workflows/create-release-tag.yamlactions/checkout@v4→actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4.github/workflows/code-quality.yamlactions/checkout@v4→actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4