Skip to content

Conversation

@manandbytes
Copy link
Contributor

Screenshot of worjflow run

@cstamas
Copy link
Collaborator

cstamas commented Jan 27, 2026

While I like this PR overall, I have one problem with it: use of external action: hoverkraft-tech/compose-action. In general I try to avoid these, but if I have to use them, I like to lock them down by hash, as GH had issues with other approaches. I do trust GH or my own actions, but not third party (for unwanted changes creeping in).

Copy link
Collaborator

@cstamas cstamas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In general I avoid third party actions, but if they are needed, use them with most caution and lock them down with hashes.

@manandbytes manandbytes force-pushed the ghw-use-docker-compose branch from 00cc9a9 to e29c713 Compare January 28, 2026 00:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants