Skip to content

fix: decouple Dependabot action fixtures from old SHAs#49

Merged
FanaticPythoner merged 1 commit into
masterfrom
fix/issue-47-fix-dependabot-blockers
May 30, 2026
Merged

fix: decouple Dependabot action fixtures from old SHAs#49
FanaticPythoner merged 1 commit into
masterfrom
fix/issue-47-fix-dependabot-blockers

Conversation

@FanaticPythoner

Copy link
Copy Markdown
Owner

Replace exact old action SHA fixture rewrites with action-name based revision mutation so Dependabot PR heads and the base workflow share the same security workflow contract.

Centralize full-SHA validation and add fixture error coverage for invalid revisions and missing action references.

Fixes #47

Replace exact old action SHA fixture rewrites with action-name based
revision mutation so Dependabot PR heads and the base workflow share
the same security workflow contract.

Centralize full-SHA validation and add fixture error coverage for
invalid revisions and missing action references.

Fixes #47
@FanaticPythoner FanaticPythoner merged commit 5c286e6 into master May 30, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix Dependabot blockers

1 participant