-
Notifications
You must be signed in to change notification settings - Fork 171
Open
Labels
status:triageIssue that has not been triagedIssue that has not been triagedtype:bugSomething isn't workingSomething isn't working
Description
Describe the bug
Security best practices dictate that githuib repositories should activate the feature:
"Require actions to be pinned to a full-length commit SHA "
All the actions I use continue to run after activating that setting except:
4876e96
To Reproduce
Use
4876e96
Activate Settings > Actions > General > Action permissions > "Require actions to be pinned to a full-length commit SHA "
Github will refuse to run the action because it does not pin it's internal dependencies.
Expected behavior
It should just work
Have you ever heard of dependabot? or renovate?
Metadata
Metadata
Assignees
Labels
status:triageIssue that has not been triagedIssue that has not been triagedtype:bugSomething isn't workingSomething isn't working