Skip to content

Pin GitHub Actions to commit SHAs#1

Merged
mrecachinas merged 1 commit into
masterfrom
pinner/actions-sha-pins
May 25, 2026
Merged

Pin GitHub Actions to commit SHAs#1
mrecachinas merged 1 commit into
masterfrom
pinner/actions-sha-pins

Conversation

@mrecachinas
Copy link
Copy Markdown
Owner

Pins GitHub Actions uses: references in mrecachinas/sigplot-bitarray to immutable commit SHAs.

Summary

Metric Count
Files changed 1
Files scanned 1
Refs found 1
Refs pinned 1
Skipped refs 1
Warnings 0
Errors 0

Why

Pinning actions to full commit SHAs prevents future tag or branch retargeting from changing workflow behavior without review.

Reviewer notes

  • Original refs are preserved in inline comments when possible.
  • Pin comments use the Dependabot-compatible original-ref style.
  • Branch refs are skipped by default unless --allow-branch-pins is used.
  • No minimum action age was enforced for this run.

Pinned refs

Location Before After Resolved as
.github/workflows/rust.yml:23 jetli/wasm-pack-action@v0.3.0 jetli/wasm-pack-action@f98777369a49686b132a9e8f0fdd59837bf3c3fd tag

Skipped refs

Location Ref Reason
.github/workflows/rust.yml:21 actions/checkout@v2 owner 'actions' is skipped by policy

Generated by pinner 0.1.0.

@mrecachinas mrecachinas merged commit fe28009 into master May 25, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant