-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
Hi 👋
I noticed the workflows reference Actions using version tags (e.g. actions/checkout@v4) rather than full commit SHAs.
Would you be open to pinning them to specific SHAs? This can help with certain automated security checks (e.g., OpenSSF Scorecard).
I’d be happy to open a PR updating the workflows accordingly.
Thanks!
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
Type
Fields
Give feedbackNo fields configured for issues without a type.