ci: pin checkout, setup-node, setup-python +1 more to commit SHA#62
Conversation
|
Warning Rate limit exceeded
To keep reviews running without waiting, you can enable usage-based add-on for your organization. This allows additional reviews beyond the hourly cap. Account admins can enable it under billing. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
git-steer: Pin GitHub Actions to commit SHAs
Pins unpinned
uses:references to their full commit SHA to prevent supply-chain attacks.Changes
.github/workflows/achievement-tracker.yml
actions/checkout@v3→@f43a0e5...actions/setup-node@v3→@3235b87....github/workflows/security.yml
actions/checkout@v4→@34e1148...actions/setup-node@v4→@49933ea...actions/setup-python@v5→@a26af69...snyk/actions/node@master→@9cf6ca7...