AspNetCore.Docs icon indicating copy to clipboard operation
AspNetCore.Docs copied to clipboard

Pin GH Actions to SHAs?

Open guardrex opened this issue 8 months ago • 3 comments

@Rick-Anderson @tdykstra @wadepickett (cc: @adegeo) ... In the Blazor samples repo, I pinned GH Actions to their SHAs and currently plan to update them annually, which I'm going to discuss with DR and Larry offline shortly. Just wanted to make sure that you saw https://github.com/dotnet/aspnetcore/pull/60948. My PR is at https://github.com/dotnet/blazor-samples/pull/492. If you want to proceed with similar steps here, this issue can serve to track it (and I'll take care of the two Blazor Actions). If not, please close this.

guardrex avatar Mar 16 '25 13:03 guardrex

This is mandatory and should be done ASAP.

adegeo avatar Mar 26 '25 18:03 adegeo

@guardrex @adegeo where are the workflows in https://github.com/dotnet/AspNetCore.Docs.Samples? It doesn't have a .github/ folder

Rick-Anderson avatar Apr 18 '25 23:04 Rick-Anderson

I don't think that repo requires any work to address this AFAICT.

guardrex avatar Apr 18 '25 23:04 guardrex