Skip to content

MAINT, CI: pin actions/setup-python#83

Open
tylerjereddy wants to merge 1 commit intomainfrom
treddy_issue_80_some_hashes
Open

MAINT, CI: pin actions/setup-python#83
tylerjereddy wants to merge 1 commit intomainfrom
treddy_issue_80_some_hashes

Conversation

@tylerjereddy
Copy link
Copy Markdown
Collaborator

* Related to a small piece of gh-80.

* Pin `actions/setup-python` for the reasons described in the matching
issue. `dependabot` should then respect our desire to use hashes
for security reasons when doing future version bumps.

* The hash for the latest stable release pinned here can be found at:
https://github.com/actions/setup-python/releases/tag/v6.2.0

* An example of this usage/pinning upstream:
https://github.com/scipy/scipy/blob/main/.github/workflows/linux.yml#L53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant