Skip to content

MNT: Use hash for Action workflow versions and update, and add dependabot, if needed#1646

Open
pllim wants to merge 3 commits into
spacetelescope:developfrom
pllim:action-ver-hash
Open

MNT: Use hash for Action workflow versions and update, and add dependabot, if needed#1646
pllim wants to merge 3 commits into
spacetelescope:developfrom
pllim:action-ver-hash

Conversation

@pllim

@pllim pllim commented Sep 30, 2024

Copy link
Copy Markdown

As recommended by https://scientific-python.org/specs/spec-0008/#pin-github-actions-release-workflows-to-their-full-release-commit-shas , this PR changes your Actions workflow version pins to hashes, and updates to latest release hashes (at the time of writing) if needed. Also adds a dependabot.yml file to enable future automatic updates of GitHub Actions workflow(s) in this repository, if needed.

This is an automated update made by the batchpr tool 🤖 - feel free to close if it doesn't look good! You can report issues to @pllim.

👻

@mfixstsci

Copy link
Copy Markdown
Collaborator

@pllim I am just getting around to this -- sorry for the delay. I am curious if merging this makes sense now, will a new hash be assigned and PR submitted once this is merged? Also @zacharyburnett noticed that we don't use dumai and now we have a conflict with build.yml.

@pllim

pllim commented Jan 22, 2025

Copy link
Copy Markdown
Author

Dependabot will do updates after this is merge so outdated hash is not an issue if you pay attention to follow up PR from Dependabot.

@pllim

pllim commented Jan 22, 2025

Copy link
Copy Markdown
Author

I resolved conflict but I recommend you use the "squash and merge" button for clean history. Thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants