Skip to content

chore: pin third-party GitHub Actions to SHAs + enable Dependabot#368

Merged
mahangu merged 2 commits into
trunkfrom
chore/devprod-1073-pin-github-actions-shas
Jun 2, 2026
Merged

chore: pin third-party GitHub Actions to SHAs + enable Dependabot#368
mahangu merged 2 commits into
trunkfrom
chore/devprod-1073-pin-github-actions-shas

Conversation

@mahangu
Copy link
Copy Markdown
Member

@mahangu mahangu commented Jun 2, 2026

Pins third-party GitHub Actions to commit SHAs and adds Dependabot coverage for the github-actions ecosystem.

Tracking: DEVPROD-1073

Verification commands:

# shivammathur/setup-php # 2.37.1
gh api repos/shivammathur/setup-php/commits/2.37.1 --jq '{ref:"2.37.1",resolved_sha:.sha,expected_sha:"7c071dfe9dc99bdf297fa79cb49ea005b9fcadbc",matches:(.sha=="7c071dfe9dc99bdf297fa79cb49ea005b9fcadbc")}'

Dependabot: created .github/dependabot.yml.

mahangu added 2 commits June 2, 2026 13:38
Hardens third-party GitHub Actions against mutable-tag supply-chain risk and
adds Dependabot coverage so pinned actions can be updated.

Tracking: DEVPROD-1073
@mahangu mahangu merged commit 3ff5786 into trunk Jun 2, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant