Skip to content

chore: add Dependabot for Actions SHA pinning#2

Open
eqdmc-admin wants to merge 1 commit into
mainfrom
feat/dependabot-actions-pinning
Open

chore: add Dependabot for Actions SHA pinning#2
eqdmc-admin wants to merge 1 commit into
mainfrom
feat/dependabot-actions-pinning

Conversation

@eqdmc-admin

Copy link
Copy Markdown
Collaborator

Adds .github/dependabot.yml to keep GitHub Actions tags pinned to commit SHAs automatically.

Weekly PRs when upstream actions have new commits — prevents supply chain attacks where a tag is silently moved.

Industry standard as of April 2026 per GitHub security hardening guide.

Co-Authored-By: Claude noreply@anthropic.com

Weekly PRs to pin action tags to commit SHAs,
preventing supply chain drift.

Co-Authored-By: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant