Skip to content

Pin Github Actions and Node.js version #2932

@Sendouc

Description

@Sendouc

For better reproductions and countering supply chain attacks it might be good idea to pin Node.js and Github Actions. Pinning part is easy but somehow the updating needs to be automated too. Dependabot has no support for either at the time of the writing.

Discussion on Discord: https://discord.com/channels/299182152161951744/784073459516964954/1488591620063629403

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedAnyone is free to pick up this issue

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions