ci(workflows): pin GitHub Actions dependencies to commit SHAs#31
ci(workflows): pin GitHub Actions dependencies to commit SHAs#31gkorland wants to merge 1 commit into
Conversation
Pin all third-party GitHub Actions to their full commit SHA instead of mutable version tags. This is a supply-chain security best practice that prevents tag-mutation attacks. Changed files: ci.yml, pypi-publish.yaml, spellcheck.yml Total actions pinned: 7 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Warning Rate limit exceeded
⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (3)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #31 +/- ##
=======================================
Coverage 86.53% 86.53%
=======================================
Files 1 1
Lines 52 52
=======================================
Hits 45 45
Misses 7 7
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
Summary
Pin all third-party GitHub Actions to their full commit SHA for supply-chain security.
Changes
Changed Files
.github/workflows/ci.yml.github/workflows/pypi-publish.yaml.github/workflows/spellcheck.ymlTesting
@refportion ofuses:directives is modifiedMemory / Performance Impact
N/A - CI configuration only.
Related Issues
Closes #30