Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pin github actions using shas #6052

Merged
merged 4 commits into from
Jan 3, 2024

Conversation

sunjayBhatia
Copy link
Member

Dependabot should be able to update these and preserve the tag in the comment, as per: dependabot/dependabot-core#5951

Workflows updated with: https://app.stepsecurity.io/secureworkflow

Dependabot should be able to update these and preserve the tag in the comment, as per: dependabot/dependabot-core#5951

Workflows updated with: https://app.stepsecurity.io/secureworkflow

Signed-off-by: Sunjay Bhatia <sunjayb@vmware.com>
@sunjayBhatia sunjayBhatia added the release-note/none-required Marks a PR as not requiring a release note. Should only be used for very small changes. label Jan 3, 2024
@sunjayBhatia sunjayBhatia requested a review from a team as a code owner January 3, 2024 19:08
@sunjayBhatia sunjayBhatia requested review from tsaarni, stevesloka, a team, davinci26, clayton-gonsalves and skriss and removed request for a team January 3, 2024 19:08
@sunjayBhatia
Copy link
Member Author

🤞🏽 this doesn't break any actions

Changing to the v2 tag/commit to see if that lets the workflow run properly

Signed-off-by: Sunjay Bhatia <sunjayb@vmware.com>
Signed-off-by: Sunjay Bhatia <sunjayb@vmware.com>
Copy link

codecov bot commented Jan 3, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (054d169) 78.77% compared to head (2af6662) 78.77%.

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##             main    #6052   +/-   ##
=======================================
  Coverage   78.77%   78.77%           
=======================================
  Files         138      138           
  Lines       19747    19747           
=======================================
  Hits        15555    15555           
  Misses       3888     3888           
  Partials      304      304           

Signed-off-by: Sunjay Bhatia <sunjayb@vmware.com>
Copy link
Member

@skriss skriss left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, glad dependabot will be updating these for us

@sunjayBhatia sunjayBhatia merged commit 8d63b86 into projectcontour:main Jan 3, 2024
26 checks passed
@sunjayBhatia sunjayBhatia deleted the pin-github-actions branch January 3, 2024 23:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
release-note/none-required Marks a PR as not requiring a release note. Should only be used for very small changes.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants