Skip to content

Conversation

@vishesh92
Copy link
Member

Pin github actions version for setup-opentofu as per https://github.com/apache/infrastructure-actions/blob/main/actions.yml

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR pins the GitHub Actions version for the setup-opentofu action to a specific commit hash to improve security and reproducibility, following Apache Infrastructure guidelines.

  • Replaces the floating tag @v1 with a pinned commit hash @000eeb8522f0572907c393e8151076c205fdba1b corresponding to v1.0.6

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

Copy link
Contributor

@DaanHoogland DaanHoogland left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

clgtm

Copy link
Collaborator

@kiranchavala kiranchavala left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kiranchavala kiranchavala merged commit e0ebb87 into apache:main Aug 26, 2025
23 checks passed
@vishesh92 vishesh92 deleted the pin-gha branch August 26, 2025 07:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants