Skip to content

ci: pin workflow dependencies - #6

Merged
imran-siddique merged 1 commit into
mainfrom
agent/pin-actions
Aug 18, 2026
Merged

ci: pin workflow dependencies#6
imran-siddique merged 1 commit into
mainfrom
agent/pin-actions

Conversation

@imran-siddique

Copy link
Copy Markdown
Member

Pins every external GitHub Action to a reviewed immutable commit and moves CodeQL security-events permission from workflow scope to the analyze job. This addresses the actionable OpenSSF Scorecard findings without changing runtime code. Validation: repository-gate tests pass locally; protected Python 3.10-3.13 and CodeQL checks are required before merge.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@imran-siddique
imran-siddique merged commit ffa416f into main Aug 18, 2026
7 checks passed
@imran-siddique
imran-siddique deleted the agent/pin-actions branch August 18, 2026 20:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant