fix(ci): pin dependency-audit reusable workflow to SHA#120
fix(ci): pin dependency-audit reusable workflow to SHA#120
Conversation
|
There was a problem hiding this comment.
Pull request overview
Pins the org reusable workflow reference in the dependency audit workflow to an immutable commit SHA to satisfy the action-pinning compliance policy (closes #89).
Changes:
- Updated
.github/workflows/dependency-audit.ymlto use@ee22b427cbce9ecadcf2b436acb57c3adf0cb63dinstead of the mutable@v1tag.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 52 minutes and 7 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |



Pins the reusable workflow reference in
.github/workflows/dependency-audit.ymlfrom the mutable@v1tag to the exact commit SHAee22b427cbce9ecadcf2b436acb57c3adf0cb63d # v1, satisfying the org action-pinning policy.What changed
.github/workflows/dependency-audit.yml:uses: ...@v1→uses: ...@ee22b427cbce9ecadcf2b436acb57c3adf0cb63d # v1The SHA was resolved via:
Closes #89
Generated with Claude Code