Re: [PR] ci: pin GitHub Actions to SHAs for security [apisix]

2026-02-05 Thread via GitHub


moonming merged PR #12972:
URL: https://github.com/apache/apisix/pull/12972


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]



[PR] ci: pin GitHub Actions to SHAs for security [apisix]

2026-02-04 Thread via GitHub


janiussyafiq opened a new pull request, #12972:
URL: https://github.com/apache/apisix/pull/12972

   ### Description
   
   
   
   
   This PR transitions third-party GitHub Actions from mutable tags (e.g., 
`@v3` or `@master` to full-length, immutable commit SHAs for better security
   
    Which issue(s) this PR fixes:
   
   Fixes #12938 
   
   ### Checklist
   
   - [x] I have explained the need for this PR and the problem it solves
   - [x] I have explained the changes or the new features added to this PR
   - [ ] I have added tests corresponding to this change
   - [ ] I have updated the documentation to reflect this change
   - [x] I have verified that this change is backward compatible (If not, 
please discuss on the [APISIX mailing 
list](https://github.com/apache/apisix/tree/master#community) first)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]