Skip to content

chore: pin GitHub Actions to verified commit SHAs#2256

Merged
lianakoleva merged 1 commit into
mainfrom
chore/pin-workflow-actions
Jun 1, 2026
Merged

chore: pin GitHub Actions to verified commit SHAs#2256
lianakoleva merged 1 commit into
mainfrom
chore/pin-workflow-actions

Conversation

@bhimrazy

@bhimrazy bhimrazy commented Jun 1, 2026

Copy link
Copy Markdown
Collaborator

What does this PR do?

Pins GitHub Actions to verified commit SHAs for supply chain security.

Follows the same pattern as pytorch-lightning#21735.

Pinned references

Action Release Commit SHA
actions/checkout v6.0.2 de0fac2e4500dabe0009e67214ff5f5447ce83dd
actions/setup-python v6.2.0 a309ff8b426b58ec0e2a45f0f869d46889d02405
actions/cache v5 27d5ce7f107fe9357f9df03efb73ab90386fccae
pypa/gh-action-pypi-publish v1.14.0 cef221092ed1bacb1cc03d23a2d87d1d172e277b

@lianakoleva lianakoleva merged commit b371959 into main Jun 1, 2026
21 of 28 checks passed
@lianakoleva lianakoleva deleted the chore/pin-workflow-actions branch June 1, 2026 17:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants