-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat(GHA): Pin azure/setup-helm #11493
base: dev
Are you sure you want to change the base?
Conversation
DryRun Security SummaryThe GitHub Actions workflows were updated to improve security and reliability by implementing SHA pinning, defining specific triggered events, and automating the Helm chart release process with pinned dependency versions. Expand for full summarySummary: The provided code changes focus on improving the security and reliability of the GitHub Actions (GHA) workflows used in the repository. The key changes include:
These changes demonstrate a strong focus on security and reliability, ensuring that the GitHub Actions used in the repository are well-managed and the Helm chart release process is secure and automated. Files Changed:
Code AnalysisWe ran |
Co-authored-by: Cody Maffucci <[email protected]>
I dropped The pin is not missing that often. Keeping another config would just increase overhead. |
Add
pinact
which is able to detect unpinned GHA