Skip to content

ci: pin our deploy workflow's action refs to commit SHAs - #3

Merged
robgilbreath merged 1 commit into
masterfrom
chore/repo-standard/sha-pin
Sep 2, 2026
Merged

robgilbreath merged 1 commit into
masterfrom
chore/repo-standard/sha-pin

Conversation

@robgilbreath

Copy link
Copy Markdown

Part of pncit/.github#20 (sha_pinning_required) — see the CIPP note on pncit/.github#17.

This is the one workflow in this fork that is ours (Azure-generated for our instance; it does not exist upstream), so pinning it cannot conflict with a rebase. Every uses: is rewritten to @<commit-sha> # <tag>, same majors, nothing else touched. Line endings preserved (CRLF).

Upstream's workflows are deliberately left as-is; they get disabled at the repo level instead so they neither fail under SHA pinning nor spend runner minutes.

@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown

🔄 If you are attempting to update your CIPP-API repo please follow the instructions at: https://docs.cipp.app/setup/self-hosting-guide/updating. Are you a sponsor? Contact the helpdesk for direct assistance with updating to the latest version. It looks like you may already have a pending update PR on your fork — check your open pull requests to accept it.

⚠️ PRs cannot target the main branch directly. If you are attempting to contribute code please PR to the dev branch.

🔒 This PR will now be automatically closed due to the above rules.

@github-actions github-actions Bot closed this Sep 2, 2026
@robgilbreath
robgilbreath merged commit 9be9e84 into master Sep 2, 2026
1 check passed
@robgilbreath
robgilbreath deleted the chore/repo-standard/sha-pin branch September 2, 2026 21:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant