Skip to content

Pin CI packages to specific hashes #51

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Draft
wants to merge 38 commits into
base: main
Choose a base branch
from
Draft

Pin CI packages to specific hashes #51

wants to merge 38 commits into from

Conversation

janbridley
Copy link
Collaborator

@janbridley janbridley commented Aug 18, 2025

Description

CI has been updated to pin specific hashes of CI scripts, as per the new group standard.

Motivation and Context

Types of Changes

  • Documentation update
  • Bug fix
  • New feature
  • Breaking change1

1The change breaks (or has the potential to break) existing functionality and should be merged into the breaking branch

Checklist:

  • I am familiar with the Development Guidelines
  • The changes introduced by this pull request are covered by existing or newly introduced tests.
  • I have updated the changelog and added my name to the credits.

@janbridley janbridley mentioned this pull request Aug 19, 2025
7 tasks
@janbridley janbridley requested review from Copilot and joaander and removed request for Copilot August 19, 2025 00:08
@janbridley janbridley self-assigned this Aug 19, 2025
@joaander
Copy link
Member

pypa/gh-action-pypi-publish#378 should fix this when merged.

@janbridley janbridley changed the title Pin CI uses to specific hashes Pin CI packages to specific hashes Aug 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants