Skip to content

Conversation

@osamingo
Copy link
Owner

@osamingo osamingo commented Jan 28, 2026

Summary

  • Pin GitHub Actions to full commit SHAs using pinact
  • Add version comments for maintainability

Changes

Action Before After
actions/checkout v4 34e114876b0b11c390a56381ad16ebd13914f8d5 (v4.3.1)
actions/setup-go v5 40f1582b2485089dde7abd97c1529aa768e1baff (v5.6.0)

Why?

Pinning to a full commit SHA helps mitigate supply chain attacks by using immutable action references.

Test plan

  • CI workflow runs successfully

🤖 Generated with Claude Code

- Pin actions/checkout to v4.3.1 (34e114876b0b11c390a56381ad16ebd13914f8d5)
- Pin actions/setup-go to v5.6.0 (40f1582b2485089dde7abd97c1529aa768e1baff)
- Improve supply chain security by using immutable action references

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@osamingo osamingo self-assigned this Jan 28, 2026
@osamingo osamingo marked this pull request as ready for review January 28, 2026 16:20
@osamingo osamingo merged commit 4f836ee into main Jan 28, 2026
3 checks passed
@osamingo osamingo deleted the chore/pin-github-actions branch January 28, 2026 16:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants