Skip to content

Pin all versions #39

@aurel333

Description

@aurel333

Describe the solution you'd like
To improve supply chain security, we should pin all the versions we use in our dependencies, both github-action and Go.

Ideally the dependencies should specify the sha, but if it is not possible without degrading the experience too much then specifying the build number is an acceptable tradeoff.

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions codegoPull requests that update go code
    No fields configured for Feature.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions