Skip to content

ci: pin GitHub Actions to commit hashes#1369

Merged
ryankert01 merged 1 commit into
apache:mainfrom
ryankert01:fix/pin-github-actions-commit-hashes
Jun 1, 2026
Merged

ci: pin GitHub Actions to commit hashes#1369
ryankert01 merged 1 commit into
apache:mainfrom
ryankert01:fix/pin-github-actions-commit-hashes

Conversation

@ryankert01

@ryankert01 ryankert01 commented Jun 1, 2026

Copy link
Copy Markdown
Member

Summary

Action Pinned to
actions/checkout de0fac2e (v6)
actions/github-script ed597411 (v8)
actions/setup-python a309ff8b (v6)
actions/setup-node 49933ea5 (v4)
actions/upload-artifact 330a01c4 (v5)
github/issue-labeler c1b0f9f5 (v3.4)
astral-sh/setup-uv 08807647 (v8.1.0)
dtolnay/rust-toolchain 29eef336 (stable)
lycheeverse/lychee-action already pinned

Test plan

  • Verify all CI workflows pass on this PR

Resolves apache#1368. All third-party actions are pinned to their full 40-char
commit SHA (with version tag preserved as a comment) and verified against
the Apache infrastructure-actions allowlist.
@ryankert01 ryankert01 force-pushed the fix/pin-github-actions-commit-hashes branch from 5d8c4fc to 8cb57c2 Compare June 1, 2026 09:19
@ryankert01 ryankert01 changed the title ci: pin GitHub Actions to commit hashes (fix #1368) ci: pin GitHub Actions to commit hashes Jun 1, 2026
@ryankert01 ryankert01 merged commit 165c959 into apache:main Jun 1, 2026
11 checks passed
@ryankert01 ryankert01 deleted the fix/pin-github-actions-commit-hashes branch June 1, 2026 09:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant