Skip to content
This repository was archived by the owner on Apr 21, 2026. It is now read-only.

ci: pin GitHub Actions to SHA, add cargo to dependabot#163

Merged
zerosnacks merged 1 commit into
mainfrom
georgen/pin-actions-dependabot
Apr 15, 2026
Merged

ci: pin GitHub Actions to SHA, add cargo to dependabot#163
zerosnacks merged 1 commit into
mainfrom
georgen/pin-actions-dependabot

Conversation

@decofe

@decofe decofe commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

Pin 9 unpinned actions to SHA, fix 6 stale version comments, add cargo ecosystem + cooldown to Dependabot.

  • actions/checkout@v6 → SHA v6.0.2 (7×)
  • github/codeql-action/*@v4 → SHA v4.35.1 (2×)
  • taiki-e/install-action SHA updated to v2.75.0
  • Swatinem/rust-cache comment # v2# v2.9.1 (5×)
  • Add cargo to dependabot.yml with 7-day cooldown

Prompted by: georgen

Co-Authored-By: grandizzy <38490174+grandizzy@users.noreply.github.com>
@zerosnacks zerosnacks merged commit 55f3dfa into main Apr 15, 2026
11 checks passed
@zerosnacks zerosnacks deleted the georgen/pin-actions-dependabot branch April 15, 2026 10:19
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants