Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: pin action versions by sha #19

Merged
merged 2 commits into from
Nov 22, 2024
Merged

ci: pin action versions by sha #19

merged 2 commits into from
Nov 22, 2024

Conversation

ewanharris
Copy link
Member

Description

We already do this in https://github.com/openfga/action-openfga-deploy but not here, we should pin by sha to improve the security of these actions as a tag is immutable and can be changed,

References

Review Checklist

  • I have clicked on "allow edits by maintainers".
  • I have added documentation for new/changed functionality in this PR or in a PR to openfga.dev [Provide a link to any relevant PRs in the references section above]
  • The correct base branch is being used, if not main
  • I have added tests to validate that the change in functionality is working as expected

If you haven't done so yet, we would appreciate it if you could star the OpenFGA repository. :)

@ewanharris ewanharris requested a review from a team as a code owner November 18, 2024 21:33
@rhamzeh rhamzeh merged commit 1785a0a into main Nov 22, 2024
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants