Skip to content

Pin GitHub Actions dependencies#225

Open
cthoyt wants to merge 1 commit into
IUPAC-InChI:devfrom
cthoyt:pin-gha-deps
Open

Pin GitHub Actions dependencies#225
cthoyt wants to merge 1 commit into
IUPAC-InChI:devfrom
cthoyt:pin-gha-deps

Conversation

@cthoyt

@cthoyt cthoyt commented Jun 15, 2026

Copy link
Copy Markdown

GitHub actions does not have a principled approach to locking versions, which poses both a security risk to supply chain attacks, and more often, annoyance to developers when things change.

This PR runs pinact (https://github.com/suzuki-shunsuke/pinact) to pin the GitHub Actions components to the specific commit corresponding to each version. This isn't perfect for security either, but it's at least a good step

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant