Skip to content

chore: migrate to pinned actions#93

Open
remyleone wants to merge 2 commits into
mainfrom
actions_up
Open

chore: migrate to pinned actions#93
remyleone wants to merge 2 commits into
mainfrom
actions_up

Conversation

@remyleone

Copy link
Copy Markdown
Member

No description provided.

Copilot AI review requested due to automatic review settings February 9, 2026 13:32

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR migrates several GitHub Actions workflow steps from floating version tags to pinned commit SHAs to improve supply-chain security and build reproducibility.

Changes:

  • Pin actions/checkout and actions/setup-python to specific commit SHAs across multiple workflows.
  • Pin third-party actions used for linting/formatting and releases (e.g., Ruff action, gh-release, create-pull-request) to commit SHAs.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
.github/workflows/typing.yml Pins checkout/setup-python to commit SHAs for typing jobs.
.github/workflows/release.yml Pins checkout/setup-python and release-related actions to commit SHAs.
.github/workflows/lint.yml Pins checkout and ruff-action to commit SHAs.
.github/workflows/format.yml Pins checkout and ruff-action to commit SHAs.
.github/workflows/extra-docs-linting.yml Pins checkout/setup-python to commit SHAs.
.github/workflows/ansible-test-units.yml Pins checkout/setup-python to commit SHAs.
.github/workflows/ansible-test-integration.yml Pins checkout/setup-python to commit SHAs.
.github/workflows/ansible-lint.yml Pins checkout to a commit SHA (but leaves ansible/ansible-lint@main unpinned).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/ansible-lint.yml Outdated
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants