-
Notifications
You must be signed in to change notification settings - Fork 1.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
🌱 Improve github actions dependencies versions and permissions #2715
🌱 Improve github actions dependencies versions and permissions #2715
Conversation
Signed-off-by: Vince Prignano <vincepri@redhat.com>
/retest |
jobs: | ||
verify: | ||
runs-on: ubuntu-latest | ||
name: verify PR contents | ||
steps: | ||
- name: Verifier action | ||
id: verifier | ||
uses: kubernetes-sigs/kubebuilder-release-tools@v0.4.3 | ||
uses: kubernetes-sigs/kubebuilder-release-tools@012269a88fa4c034a0acf1ba84c26b195c0dbab4 # tag=v0.4.3 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why not use the tags?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
These are pinned dependencies, to a hash. Versions might change the hash and that on its own has general security implications.
When updates are available, dependabot updates both the hash and the tag comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
A while back dependabot didn't support updating tag comments, but since that's supported we've been using this in CAPI and it works perfectly
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: alvaroaleman, vincepri The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
No description provided.