Skip to content

Do not work when new GitHub policy to pin actions by full SHA is enabled #757

@fraxken

Description

@fraxken

Context

When the new GitHub policy to enforce actions to be pinned by full SHA is enabled then github-action-merge-dependabot stop working because the two dependencies in action.yml are not pinned.

The workflow throw with the following error
Image

In the light of how impactful security issues (supply-chain attacks) with actions are nowadays I think this should be fixed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions