Skip to content

Pin GitHub Actions to commit SHAs#2

Merged
mrecachinas merged 1 commit into
masterfrom
pinner/actions-sha-pins
May 25, 2026
Merged

Pin GitHub Actions to commit SHAs#2
mrecachinas merged 1 commit into
masterfrom
pinner/actions-sha-pins

Conversation

@mrecachinas
Copy link
Copy Markdown
Owner

Pins GitHub Actions uses: references in mrecachinas/sigplot-bitarray to immutable commit SHAs.

Summary

Metric Count
Files changed 1
Files scanned 1
Refs found 1
Refs pinned 1
Skipped refs 1
Warnings 0
Errors 0

Why

Pinning actions to full commit SHAs prevents future tag or branch retargeting from changing workflow behavior without review.

Reviewer notes

  • Original refs are preserved in inline comments when possible.
  • Pin comments use the Dependabot-compatible original-ref style.
  • Branch refs are skipped by default unless --allow-branch-pins is used.
  • No minimum action age was enforced for this run.

Pinned refs

Location Before After Resolved as
.github/workflows/rust.yml:21 actions/checkout@v2 actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 tag

Skipped refs

Location Ref Reason
.github/workflows/rust.yml:23 jetli/wasm-pack-action@f98777369a49686b132a9e8f0fdd59837bf3c3fd already pinned to a full SHA

Generated by pinner 0.1.0.

@mrecachinas mrecachinas merged commit 08a3e75 into master May 25, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant