Skip to content

Use renovate and pinned hashes for GitHub Actions#3043

Merged
messense merged 1 commit into
mainfrom
konsti/renovate-and-pinned-hashes
Feb 26, 2026
Merged

Use renovate and pinned hashes for GitHub Actions#3043
messense merged 1 commit into
mainfrom
konsti/renovate-and-pinned-hashes

Conversation

@konstin

@konstin konstin commented Feb 26, 2026

Copy link
Copy Markdown
Member

We're trying to improve supply chain security by avoiding compromised GitHub Actions, so we pin the actions. I've also migrated from dependabot to renovate, which has proper support for this built-in (helpers:pinGitHubActionDigests) and allows better configuration than dependabot.

We're trying to improve supply chain security by avoiding compromised GitHub Actions, so we pin the actions. I've also migrated from dependabot to renovate, which has proper support for this built-in (`helpers:pinGitHubActionDigests`) and allows better configuration than dependabot.
@konstin konstin force-pushed the konsti/renovate-and-pinned-hashes branch from bf8f51e to de8c824 Compare February 26, 2026 10:56
@konstin konstin requested a review from messense February 26, 2026 10:59

@messense messense left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@messense messense enabled auto-merge (squash) February 26, 2026 11:05
@messense messense merged commit 1e1bc0d into main Feb 26, 2026
64 checks passed
@messense messense deleted the konsti/renovate-and-pinned-hashes branch February 26, 2026 12:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants