Skip to content

Conversation

@nschonni
Copy link
Contributor

@nschonni nschonni commented Mar 24, 2025

Preview Tests

There was a ecosystem issue by tj-actions the other week which caused secrets to be spilled from CI logs. That action didn't affect this repo, but since it is part of the recommended hardening, I run npx pin-github-action .github/workflows/ to pin them. Dependabot should still create PRs to bump them as needed

@howard-e
Copy link
Contributor

@nschonni very interesting! I had only seen this notice in passing but didn't check further.

Thanks for sharing this. As stated, this repo doesn't seem affected but will monitor the discourse around it and see if we should move this forward (or in any other repos, ha)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants