-
Notifications
You must be signed in to change notification settings - Fork 178
Open
Description
Enabling this will make it easier to use this action in a secure way, with mutable tags I need to either fork this action or pin to a Git SHA to ensure that I am using a known version of this action, with an immutable release I can pin to the tag and be confident the code won't be maliciously modified due to a compromise of this repo.
It also makes it easier to understand what version we are using in workflows as we can view the version number instead of a sha
Metadata
Metadata
Assignees
Labels
No labels