Commit Graph

10 Commits

Author SHA1 Message Date
Jake Barnby 708aea2532 chore: pin github actions to sha and bump to latest
Pin every third-party action in .github/workflows/ to a full commit SHA
with a trailing version comment, and bump to the latest stable release.
Defends against tag-rewrite supply-chain attacks while keeping versions
legible.
2026-05-08 01:07:12 +12:00
loks0n 4326600751 Refactor CI workflows: add COMPOSE_FILE env, add build targets, bump action versions, pin composer
- Add COMPOSE_FILE=docker-compose.yml to tests, benchmark, and sdk-preview to prevent loading overrides in CI
- Add target: development to tests/benchmark builds, target: production to pr-scan/nightly builds
- Bump actions/checkout v4→v6, docker/build-push-action v4/v5→v6, actions/upload-artifact v4→v6, actions/github-script v7→v8
- Pin composer images to 2.8 in linter and static-analysis workflows

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-13 00:56:03 +00:00
Matej Bačo 733e0498a7 AI-recommended changes 2025-04-16 11:50:42 +02:00
Christy Jacob f8b89b2294 Merge pull request #3728 from sashashura/patch-1
GitHub Workflows security hardening
2024-12-11 20:25:22 +04:00
Steven Nguyen 7f542e2052 Update the github workflows to cancel if PR is modified 2023-02-21 14:59:15 -08:00
Christy Jacob 1e94400a7b Merge pull request #4332 from Sushrut1101/master
workflows: Update actions/checkout to v3
2022-12-20 13:23:08 +05:30
Sarthak Roy c57da64feb workflows: Update codeql-action to v3 2022-10-19 21:59:12 +05:30
Sushrut1101 a0d1a12f1e workflows: Update actions/checkout to v3 2022-10-08 12:32:58 +05:30
Alex e4d8d38c6e Update codeql-analysis.yml
Signed-off-by: sashashura <93376818+sashashura@users.noreply.github.com>
2022-08-29 11:34:32 +01:00
Eldad A. Fux 42341fddbb Create codeql-analysis.yml 2020-09-10 13:07:28 +03:00