Skip to content

Comments

chore: Pin GitHub Actions to commit SHAs#9165

Open
pgoslatara wants to merge 1 commit intotoeverything:mainfrom
pgoslatara:actup/pin-actions-to-sha-1771518261
Open

chore: Pin GitHub Actions to commit SHAs#9165
pgoslatara wants to merge 1 commit intotoeverything:mainfrom
pgoslatara:actup/pin-actions-to-sha-1771518261

Conversation

@pgoslatara
Copy link

This PR pins GitHub Actions to exact commit SHAs for more reproducible builds.

Why pin to commit SHAs?

Pinning GitHub Actions to specific commit SHAs ensures your workflow uses the exact same version every time, preventing unexpected changes when an action publisher releases a new version. This improves security and reliability.

Learn more: https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions

Changes

  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/size-report.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/sync-blocksuite.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/canary-release.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/pr-title-lint.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/codeql-analysis.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/size-report.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/test.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/pr-title-lint.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/canary-release.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/sync-blocksuite.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/test.yml
  • Pinned peter-evans/create-pull-request from v7 to 22a9089 in .github/workflows/sync-blocksuite.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/codeql-analysis.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/release.yml
  • Pinned actions/checkout from v4 to 34e1148 in .github/workflows/release.yml

@vercel
Copy link

vercel bot commented Feb 19, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
blocksuite Ready Ready Preview, Comment Feb 19, 2026 4:27pm

Request Review

@vercel
Copy link

vercel bot commented Feb 19, 2026

@pgoslatara is attempting to deploy a commit to the toeverything Team on Vercel.

A member of the Team first needs to authorize it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

1 participant