Skip to content

ci: Pin GitHub Actions and Go tools to commit hashes#262

Open
cuixq wants to merge 2 commits intopypa:mainfrom
cuixq:workflow
Open

ci: Pin GitHub Actions and Go tools to commit hashes#262
cuixq wants to merge 2 commits intopypa:mainfrom
cuixq:workflow

Conversation

@cuixq
Copy link
Contributor

@cuixq cuixq commented Mar 4, 2026

This PR improves the security of CI workflows by pinning GitHub Actions and Go tools to specific commit hashes.

  • auto_import.yaml:
    • Pinned actions/checkout to v6.0.2.
    • Pinned actions/setup-go to v6.3.0.
    • Pinned osv/vulnfeeds/cmd/pypi to the latest master hash..
  • automation.yaml:

@cuixq cuixq marked this pull request as ready for review March 4, 2026 04:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant