ci(workflows): pin GitHub Actions dependencies to commit SHAs#5
ci(workflows): pin GitHub Actions dependencies to commit SHAs#5shahar-biron merged 1 commit intomainfrom
Conversation
Pin all third-party GitHub Actions to their full commit SHA instead of mutable version tags. This is a supply-chain security best practice that prevents tag-mutation attacks. Changed files: php.yml, spellcheck.yml Total actions pinned: 7 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Warning Rate limit exceeded
⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #5 +/- ##
=========================================
Coverage 51.69% 51.69%
Complexity 333 333
=========================================
Files 16 16
Lines 766 766
=========================================
Hits 396 396
Misses 370 370 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Summary
Pin all third-party GitHub Actions to their full commit SHA for supply-chain security.
Changes
Changed Files
.github/workflows/php.yml.github/workflows/spellcheck.ymlTesting
@refportion ofuses:directives is modifiedMemory / Performance Impact
N/A - CI configuration only.
Related Issues
Closes #4