Skip to content

Conversation

@CommanderStorm
Copy link
Member

Launch Checklist

Our CI uses a few actions.
For these actions, we currently just use the mutable GitHub tag.

Since we use Dependabot to update the versions, we should use SHAs.
This makes sure that we are not affected by a certain class of supply chain vulnerability where attackers re-publish bad tags.

Using SHAs matches GitHub recommendations and is a part of the OpenSSFs Scorecard.

  • Confirm your changes do not include backports from Mapbox projects (unless with compliant license) - if you are not sure about this, please ask!
  • Add an entry to CHANGELOG.md under the ## main section.
    ^--- not sure if you want this. Other maintenance actions don't show up as well.

@HarelM HarelM merged commit 72a310d into maplibre:main Oct 10, 2025
1 check passed
@CommanderStorm CommanderStorm deleted the pin branch October 10, 2025 13:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants