Skip to content

Comments

Pin the actions/setup-python for the externally used action.yml#2749

Open
cgravill wants to merge 1 commit intopypa:mainfrom
cgravill:pin_setup-python_action
Open

Pin the actions/setup-python for the externally used action.yml#2749
cgravill wants to merge 1 commit intopypa:mainfrom
cgravill:pin_setup-python_action

Conversation

@cgravill
Copy link

Minimal variation on #2744 by @agriyakhetarpal

I'm working on a project that has "Require actions to be pinned to a full-length commit SHA" enabled. I've used cibuildwheel on other projects and it's been really useful, thanks! Unfortunately the requirement for SHA pining then blocks using the cibuildwheel.

I saw on #2744 there's concerns about pinning everything, but potentially willing to pin the release part.

While I can use my fork in the project it'd be great to get this focused change in to reduce complications for folks with that setting on.

@agriyakhetarpal
Copy link
Member

Thanks for splitting this off my PR, @cgravill! I will approve this, but will ask either @henryiii or @joerick to sign it off and press merge.

@henryiii
Copy link
Contributor

I still would like to get our CI fixed :)

Yes, I'm fine with this, certainly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants