Skip to content

Conversation

@joeparsons
Copy link
Member

Description

  • Pins all third-party GitHub actions in workflows to specific revision hashes with a human readable version comment that should be compatible with dependabot.
    • This will make using pinned versions of third-party actions a more manageable and improve the developer UX for reviewing dependadabot PRs that update these.
  • Enables dependabot updates for github-actions with the cooldown option enabled to require new versions be at least 5 days old before dependabot will create PR to update them (to further enhance supply chain security).

This PR should also be backported to the 1.x branch.

Related issues

Closes #133

…hashes, enable dependabot updates for github-actions.
@joeparsons joeparsons self-assigned this Nov 4, 2025
@joeparsons joeparsons added the enhancement New feature or request label Nov 4, 2025
@joeparsons joeparsons added dependencies Pull requests that update a dependency file ci Continuous integration / automation labels Nov 4, 2025
@joeparsons joeparsons requested a review from a team November 4, 2025 17:48
@joeparsons joeparsons added the backport Changes to be back-ported to previous development or release branch(es) label Nov 4, 2025
@joeparsons joeparsons marked this pull request as ready for review November 4, 2025 17:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport Changes to be back-ported to previous development or release branch(es) ci Continuous integration / automation dependencies Pull requests that update a dependency file enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pin third-party actions to specific releases in GitHub Actions workflows

2 participants