Skip to content

Conversation

vszakats
Copy link
Member

@vszakats vszakats commented Sep 15, 2025


To bump the pinned actions, we could enable Dependabot.

There is a brand new feature called immutable releases, and
it seems to be enabled for actions/checkout, but possibly
only for future releases (aka: not yet) (there needs to be
"🔒 Immutable" text below the title on the release page):
https://github.com/actions/checkout/releases/tag/v5.0.0
https://raw.githubusercontent.com/github/codeql/refs/heads/main/actions/ql/extensions/immutable-actions-list/ext/immutable_actions.yml
https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/immutable-releases

@vszakats vszakats marked this pull request as draft September 15, 2025 21:23
@vszakats vszakats changed the title ci: set permissions, pin actions, set persist-credentials: false ci: set permissions, pin actions, do not persists creds, add SECURITY.md Sep 15, 2025
@vszakats vszakats marked this pull request as ready for review September 15, 2025 21:40
@vszakats vszakats requested a review from xquery September 16, 2025 21:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant