Skip to content

chore: bump secure-inputs reusable workflow pin - #156

Merged
rajbos merged 2 commits into
mainfrom
chore/bump-secure-inputs-reusable-workflow
Jul 1, 2026
Merged

chore: bump secure-inputs reusable workflow pin#156
rajbos merged 2 commits into
mainfrom
chore/bump-secure-inputs-reusable-workflow

Conversation

@rajbos

Copy link
Copy Markdown
Contributor

Bumps the pinned SHA for the devops-actions/.github reusable workflow (secure-inputs.yml) to the latest main commit, which now pins secure-action-inputs to a tagged �1.0.0 release SHA instead of a floating @main ref (see devops-actions/.github#323).

Both devops-actions/.github and devops-actions/secure-action-inputs now have tagged releases, so Dependabot will also be able to auto-update this pin going forward.

Bumps the pinned SHA for devops-actions/.github's secure-inputs.yml reusable
workflow to latest main, which now pins secure-action-inputs to a tagged
v1.0.0 SHA instead of a floating @main ref (devops-actions/.github#323).
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

Tagging @rajbos for notifications

@github-actions

github-actionsBot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA f9fb3ea.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

License Issues

.github/workflows/secure-inputs.yml

PackageVersionLicenseIssue Type
devops-actions/.github/.github/workflows/secure-inputs.yml3bb5c8505eb368f90cf87956f0cc4d84cb8554d1NullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
actions/devops-actions/.github/.github/workflows/secure-inputs.yml 3bb5c8505eb368f90cf87956f0cc4d84cb8554d1 UnknownUnknown

Scanned Files

  • .github/workflows/secure-inputs.yml

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@rajbos
rajbos merged commit f2623c1 into mainJul 1, 2026
12 checks passed
@rajbos
rajbos deleted the chore/bump-secure-inputs-reusable-workflow branch July 1, 2026 20:01
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rajbos