Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build: Pin GitHub Actions #3323

Merged
merged 1 commit into from Nov 17, 2022
Merged

build: Pin GitHub Actions #3323

merged 1 commit into from Nov 17, 2022

Commits on Nov 17, 2022

  1. build: Pin GitHub Actions

    The main benefit of pinning GitHub actions is the determinism it brings
    in terms of what version of a given action will be executed. This is
    a step towards having hermetic builds.
    
    Once pinned to a commit, dependabot will automatically issue PRs to update
    to newer versions.
    
    Pinned versions is the only security metric from OpenSSF scorecard that
    this repository currently have a zero score.
    
    Signed-off-by: Paulo Gomes <paulo.gomes@weave.works>
    Paulo Gomes committed Nov 17, 2022
    Copy the full SHA
    d0e6fca View commit details
    Browse the repository at this point in the history