Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pin GitHub Actions workflows #206

Merged
merged 1 commit into from
Oct 30, 2024

Conversation

jspeed-meyers
Copy link
Collaborator

Pin the GitHub Actions workflows to a fixed version. This is part of the requirements of OpenSSF Scorecards. See issue #192.

Signed-off-by: John Speed Meyers <jsmeyers@chainguard.dev>
@goneall
Copy link
Member

goneall commented Oct 30, 2024

I'm wondering if we should update to a later version for some of the actions - e.g. checkout is now past version 4.

@jspeed-meyers - what do you think?

@jspeed-meyers
Copy link
Collaborator Author

@goneall: Sounds good to me. My thinking: If this PR gets merged, then PR #207, once merged, should handle this proposed update smoothly. Therefore, merging these two PRs is equivalent to your proposal in the long run and has the benefit of making continued updates easier for the maintainers of this project.

@goneall
Copy link
Member

goneall commented Oct 30, 2024

@goneall: Sounds good to me. My thinking: If this PR gets merged, then PR #207, once merged, should handle this proposed update smoothly. Therefore, merging these two PRs is equivalent to your proposal in the long run and has the benefit of making continued updates easier for the maintainers of this project.

Agree - I'll go ahead and approve

Copy link
Member

@goneall goneall left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jspeed-meyers
Copy link
Collaborator Author

Thank you, @goneall. Also, I should have explained my thinking in the first place. Thank you for being thoughtful and asking questions!

@jspeed-meyers jspeed-meyers merged commit 604fa76 into spdx:main Oct 30, 2024
6 checks passed
@jspeed-meyers jspeed-meyers deleted the pin-gitHub-actions-workflows branch October 30, 2024 16:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants