google / osv.dev

Open source vulnerability DB and triage service.
https://osv.dev
Apache License 2.0
1.49k stars 186 forks source link

ci: pin `actions/checkout` to a commit #2633

Closed G-Rath closed 1 week ago

G-Rath commented 1 week ago

I noticed that this hasn't been pinned, which it should be to make scorecard happier

G-Rath commented 1 week ago

(there's only one more of these to do I think 😅)

G-Rath commented 1 week ago

I think it worth to mention v3 upgraded to v4 in the PR description.

I've just reverted that, since renovate should end up doing it or otherwise I can do it in a dedicated PR later

another-rex commented 1 week ago

I'm not sure if renovate is configured to do major version updates for workflows.