Skip to content

feat(ENG-11298): Pinning GitHub actions#7

Merged
elgordomac merged 1 commit intomainfrom
eng-11298/pinning-github-actions
Dec 5, 2025
Merged

feat(ENG-11298): Pinning GitHub actions#7
elgordomac merged 1 commit intomainfrom
eng-11298/pinning-github-actions

Conversation

@elgordomac
Copy link
Copy Markdown
Contributor

@elgordomac elgordomac commented Dec 3, 2025

Summary by cubic

Pin GitHub Actions to exact versions across all workflows to improve security and reproducibility. Aligns with ENG-11298 to enforce org-wide version pinning policy.

  • Dependencies
    • actions/checkout pinned to v4.3.1
    • oven-sh/setup-bun pinned to v1.2.2 (PR and composite) and v2.0.2 (release)
    • actions/setup-node pinned to v4.4.0
    • googleapis/release-please-action pinned to v4.4.0
    • amannn/action-semantic-pull-request pinned to v5

Written for commit d4efbdb. Summary will update automatically on new commits.

Copy link
Copy Markdown

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 4 files

@elgordomac elgordomac changed the title Pinning GitHub actions feat(ENG-11298): Pinning GitHub actions Dec 3, 2025
Copy link
Copy Markdown
Contributor

@ryoppippi ryoppippi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

@elgordomac elgordomac merged commit 1dccb5d into main Dec 5, 2025
3 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants