Closed kairoaraujo closed 1 year ago
Should we also make it pinned?
I think dependabot may not handle that?
I think dependabot may not handle that?
No, it will not handle it.
I think dependabot may not handle that?
No, it will not handle it.
Could we at least semver pin it? @v1.1.1
or something?
I see that my work here duplicates https://github.com/in-toto/witness/pull/316.
Fix the github organization name to in-toto.
pin GHA full-length commit SHA
It's a good practice to pin the GitHub Actions with full-length commit sha as described in the "Security hardening for GitHub Actions". https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions
I noticed that dependabot also checks weekly with updates. It will maintain the updates using the hash.