Skip to content

Conversation

@jespino
Copy link

@jespino jespino commented Dec 15, 2025

Pin all external GitHub Actions to specific commit SHAs for supply chain security.

Changes

  • actions/checkout@v4 → pinned to SHA
  • actions/github-script@v6 → pinned to SHA
  • eifinger/setup-rye@v4 → pinned to SHA
  • pypa/gh-action-pypi-publish@release/v1 → pinned to SHA
Pin all external GitHub Actions to specific commit SHAs. Changes: - actions/checkout@v4 → pinned to SHA - actions/github-script@v6 → pinned to SHA - eifinger/setup-rye@v4 → pinned to SHA - pypa/gh-action-pypi-publish@release/v1 → pinned to SHA Co-authored-by: Ona <no-reply@ona.com>
@jespino jespino force-pushed the je/pin-github-actions branch from 66154dc to b4a2adc Compare December 15, 2025 17:30
@jespino jespino marked this pull request as ready for review December 15, 2025 17:31
Copy link

@corneliusludmann corneliusludmann left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Note: ideally this change should also be applied to the upstream Stainless SDK repo so it persists across syncs.

@corneliusludmann
Copy link

See gitpod-io/gitpod-sdk-go#69 (comment) for more context on upstream changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants