Skip to content

chore: pin GitHub Actions to verified commit SHAs#2255

Closed
bhimrazy wants to merge 1 commit into
Lightning-AI:mainfrom
bhimrazy:chore/pin-workflow-actions
Closed

chore: pin GitHub Actions to verified commit SHAs#2255
bhimrazy wants to merge 1 commit into
Lightning-AI:mainfrom
bhimrazy:chore/pin-workflow-actions

Conversation

@bhimrazy

@bhimrazy bhimrazy commented Jun 1, 2026

Copy link
Copy Markdown
Collaborator

What does this PR do?

Pins GitHub Actions to verified commit SHAs for supply chain security.

Follows the same pattern as pytorch-lightning#21735.

Pinned references

Action Release Commit SHA
actions/checkout v6.0.2 de0fac2e4500dabe0009e67214ff5f5447ce83dd
actions/setup-python v6.2.0 a309ff8b426b58ec0e2a45f0f869d46889d02405
actions/cache v5 27d5ce7f107fe9357f9df03efb73ab90386fccae
pypa/gh-action-pypi-publish v1.14.0 cef221092ed1bacb1cc03d23a2d87d1d172e277b

@bhimrazy

bhimrazy commented Jun 1, 2026

Copy link
Copy Markdown
Collaborator Author

Closing in favor of #2256

@bhimrazy bhimrazy closed this Jun 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant