chore: Pin third-party GitHub Actions to full commit SHAs#136
chore: Pin third-party GitHub Actions to full commit SHAs#136willporter-workos merged 2 commits intomainfrom
Conversation
Original prompt from will.porter
|
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
|
Warning Rate limit exceeded
To keep reviews running without waiting, you can enable usage-based add-on for your organization. This allows additional reviews beyond the hourly cap. Account admins can enable it under billing. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (4)
✨ Finishing Touches🧪 Generate unit tests (beta)
Review rate limit: 0/3 reviews remaining, refill in 9 minutes and 53 seconds. Comment |
Greptile SummaryThis PR pins all third-party GitHub Actions from floating Confidence Score: 5/5Safe to merge — changes are limited to pinning floating action tags to immutable SHAs with no logic modifications. All four workflow files are updated consistently, no functional logic is altered, and the change improves supply-chain security. No P0 or P1 findings. No files require special attention. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Push to main / PR] --> B[ci.yml]
B --> B1["actions/checkout@SHA #v4"]
B --> B2["pnpm/action-setup@SHA #v4"]
B --> B3["actions/setup-node@SHA #v4"]
A2[Push to main] --> C[release-please.yml]
C --> C1["googleapis/release-please-action@SHA #v4"]
C1 -->|release_created| D[release.yml]
D --> D1["actions/checkout@SHA #v4"]
D --> D2["pnpm/action-setup@SHA #v4"]
D --> D3["actions/setup-node@SHA #v4"]
A3[Schedule / workflow_dispatch] --> E[socket-tier1-analysis.yml]
E --> E1["actions/checkout@SHA #v4"]
E --> E2["npm install -g socket (unpinned)"]
Reviews (2): Last reviewed commit: "Fix formatting in workflow files" | Re-trigger Greptile |
Third-Party Action SHA Age Report
|
Co-Authored-By: will.porter <will.porter@workos.com>
file:///home/ubuntu/pin-actions/cli_pr_body.md
Link to Devin session: https://app.devin.ai/sessions/add87be2227046f198fbac38a32e5358