Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(ci): pin 3rd-party actions to specific commit hashes #664

Merged
merged 1 commit into from
Jan 16, 2025

Conversation

Water-Melon
Copy link
Contributor

KAG-6149

Copy link

codecov bot commented Jan 16, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 90.79446%. Comparing base (63f6784) to head (c05659a).
Report is 4 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@                 Coverage Diff                 @@
##                main        #664         +/-   ##
===================================================
- Coverage   90.82650%   90.79446%   -0.03204%     
===================================================
  Files             53          53                 
  Lines          11337       11341          +4     
  Branches        1692        1690          -2     
===================================================
  Hits           10297       10297                 
- Misses          1034        1038          +4     
  Partials           6           6                 

see 3 files with indirect coverage changes

Flag Coverage Δ
unit 90.55126% <ø> (-0.01725%) ⬇️
valgrind 82.43902% <ø> (-0.10051%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

@thibaultcha
Copy link
Member

thibaultcha commented Jan 16, 2025

Does this break our Dependabot automatic updates? If so, very much not inclined to merge this, that would be terrible. Considering this is fully open source, nobody will steal any sensitive information or code whatsoever. This repository also does not directly deliver to end-users/customers (the Gateway repo CI/CD does that), what is the benefit?

@thibaultcha
Copy link
Member

I was informed that Dependabot does support updating actions pinned with sha1 commits, in which case we are all good! Thank you.

@thibaultcha thibaultcha merged commit 0c9eeed into main Jan 16, 2025
32 checks passed
@thibaultcha thibaultcha deleted the pin_actions branch January 16, 2025 18:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants