Skip to content

[CI/Build] Pin tesslio/skill-review action to commit SHA - #2649

Open
arijitroy003 wants to merge 1 commit into
vllm-project:mainfrom
arijitroy003:fix/pin-skill-review-action
Open

[CI/Build] Pin tesslio/skill-review action to commit SHA#2649
arijitroy003 wants to merge 1 commit into
vllm-project:mainfrom
arijitroy003:fix/pin-skill-review-action

Conversation

@arijitroy003

Copy link
Copy Markdown
Contributor

Purpose

Pins the tesslio/skill-review GitHub Action from @main (mutable branch reference) to its current commit SHA to prevent supply-chain attacks and ensure reproducible CI builds.

Changes

  • Updated .github/workflows/skill-review.yml to reference tesslio/skill-review@5aefcf5e500ae13a9af904383dbb914c6c3a50e4 instead of @main
  • Added comment documenting the pinned version and date

Test Plan

N/A — verified by grep and visual inspection of workflow file.

Signed-off-by: arijitroy003 <arijitroy003@gmail.com>
@netlify

netlify Bot commented Jul 23, 2026

Copy link
Copy Markdown

Deploy Preview for vllm-semantic-router ready!

Name Link
🔨 Latest commit 440bae9
🔍 Latest deploy log https://app.netlify.com/projects/vllm-semantic-router/deploys/6a622c775087bd000722051b
😎 Deploy Preview https://deploy-preview-2649--vllm-semantic-router.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions

Copy link
Copy Markdown
Contributor

👥 vLLM Semantic Team Notification

The following members have been identified for the changed files in this PR and have been automatically assigned when their GitHub accounts are assignable in this repository:

📁 Root Directory

Owners: @rootfs, @Xunzhuo
Files changed:

  • .github/workflows/skill-review.yml

vLLM Semantic Router

🎉 Thanks for your contributions!

This comment was automatically generated based on the OWNER files in the repository.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Supply Chain Security Report — All Clear

Scanner Status Findings
AST Codebase Scan (Py, Go, JS/TS, Rust) 29 finding(s) — MEDIUM: 22 · LOW: 7
AST PR Diff Scan No issues detected
Regex Fallback Scan No issues detected

Scanned at 2026-07-23T15:03:00.211Z · View full workflow logs

@AayushSaini101

Copy link
Copy Markdown
Collaborator

thanks for the contributing, kindly create an issue and linked to the MR : )

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants