Skip to content

ci: hash pinning of actions, fix other dependencies/settings#163

Merged
mdevolde merged 1 commit into
jxmorris12:masterfrom
mdevolde:CI/security
May 10, 2026
Merged

ci: hash pinning of actions, fix other dependencies/settings#163
mdevolde merged 1 commit into
jxmorris12:masterfrom
mdevolde:CI/security

Conversation

@mdevolde

Copy link
Copy Markdown
Collaborator

ci: hash pinning of actions, fix other dependencies/settings

Why the pull request was made

In order to adopt good practices against supply chain attacks, actions in our CI are now pinned by their commit hash, and some parameters/versions were updated to increase security.

Summary of changes

  • Hash pinning of actions in our CI
  • Fix some CI dependencies versions
  • Edit some parameters in the CI to increase security

Screenshots (if appropriate):

Not applicable.

How has this been tested?

Ran the CI with new settings.

Resources

Not applicable.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update (changes to documentation only)
  • Refactor / code style update (non-breaking change that improves code structure or readability)
  • Tests / CI improvement (adding or updating tests or CI configuration only)
  • Other (please describe):

Checklist

  • Followed the project's contributing guidelines.
  • Updated any relevant tests.
  • Updated any relevant documentation.
  • Added comments to your code where necessary.
  • Formatted your code, run the linters, checked types and tests.

@mdevolde mdevolde merged commit a95d3da into jxmorris12:master May 10, 2026
8 checks passed
@mdevolde mdevolde deleted the CI/security branch May 10, 2026 17:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant