Skip to content

[SECENG-364] Pin GitHub Actions to commit SHAs#43

Open
Stephanie Ginovker (sginovker) wants to merge 1 commit into
mainfrom
security/pin-actions-to-sha
Open

[SECENG-364] Pin GitHub Actions to commit SHAs#43
Stephanie Ginovker (sginovker) wants to merge 1 commit into
mainfrom
security/pin-actions-to-sha

Conversation

@sginovker
Copy link
Copy Markdown
Contributor

@sginovker Stephanie Ginovker (sginovker) commented May 7, 2026

Ticket

SECENG-364

Summary

Dependabot

Added/updated dependabot.yml to keep GitHub Actions pinned to the latest SHA with a 7-day update cooldown. hoverinc/* is excluded from the cooldown so internal actions can auto-merge promptly.

PR Automation

Added .github/workflows/pr-automation.yml calling hoverinc/action-pr-automation to auto-merge safe dependabot PRs (dev deps and approved production deps).

@sginovker Stephanie Ginovker (sginovker) marked this pull request as ready for review May 27, 2026 22:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant