Skip to content

CI SHA-pinning #7

Description

@PhysShell

CI SHA-pinning: agreed it's a reasonable call for this PoC (recorded a "learning" to defer it to Dependabot/a hardening pass).

Activity

  1. mrpunyetaz-cloud commented on Jun 18, 2026

    @mrpunyetaz-cloud

    Duplicate of #5

  2. PhysShell commented on Jun 19, 2026

    @PhysShell
    OwnerAuthor

    @mrpunyetaz-cloud hi! please provide more details as i'm unable to see in what place it is duplicate

  3. PhysShell commented on Jul 9, 2026

    @PhysShell
    OwnerAuthor

    Agent brief (for handing this issue to a coding agent — tier: basic. One PR, Closes #7; branch from main.)

    Pin every third-party uses: owner/action@tag across the five workflows (.github/workflows/ci.yml, mine.yml, mine-on-push.yml, oracle.yml, pr-issue-validation.yml) to the full commit SHA with a trailing # vN version comment. Leave local ./ action references untouched.

    Done when: no mutable tag remains in any uses: line, the version comments make future bumps reviewable, and CI is green.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions