Skip to content

Pin GitHub Actions versions #7292

@Boosted-Bonobo

Description

@Boosted-Bonobo

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

All github actions used are done as @someVersion while also not having any lockfile for them.
The following article goes into details about this problem.
Most likely it is never going to be fixed by github, so the responsability becomes ours to improve how things stand.

Expected Behavior

Used github actions are pinned to their commit so that re-releases/re-tags do not change the output.
Actions using super-linter benefit from added provenance attestation.

Anything else?

Thank you for the explanation here.
The above issue also is related to this one: #7280

Metadata

Metadata

Assignees

No one assigned

    Labels

    O: backlog 🤖Backlog, stale ignores this labelenhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions