Skip to content
This repository was archived by the owner on Jun 12, 2026. It is now read-only.

feat(ENG-11298): Pinning GitHub actions#7

Merged
elgordomac merged 1 commit into
mainfrom
eng-11298/pinning-github-actions
Dec 5, 2025
Merged

feat(ENG-11298): Pinning GitHub actions#7
elgordomac merged 1 commit into
mainfrom
eng-11298/pinning-github-actions

Conversation

@elgordomac

@elgordomac elgordomac commented Dec 3, 2025

Copy link
Copy Markdown
Contributor

Summary by cubic

Pin GitHub Actions to exact versions across all workflows to improve security and reproducibility. Aligns with ENG-11298 to enforce org-wide version pinning policy.

  • Dependencies
    • actions/checkout pinned to v4.3.1
    • oven-sh/setup-bun pinned to v1.2.2 (PR and composite) and v2.0.2 (release)
    • actions/setup-node pinned to v4.4.0
    • googleapis/release-please-action pinned to v4.4.0
    • amannn/action-semantic-pull-request pinned to v5

Written for commit d4efbdb. Summary will update automatically on new commits.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 4 files

@elgordomac elgordomac changed the title Pinning GitHub actions feat(ENG-11298): Pinning GitHub actions Dec 3, 2025

@ryoppippi ryoppippi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

@elgordomac elgordomac merged commit 1dccb5d into main Dec 5, 2025
3 of 5 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants