Skip to content

Conversation

@james-otten-pan
Copy link
Contributor

Similar to #185 and #186

GitHub recommends pinning actions to a full length commit SHA, as this is currently the only method of using an action as an immutable release.

For more information refer to: https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions

Updated the GitHub Action for publishing to PyPI to use a specific commit SHA.
Copy link
Collaborator

@SimOnPanw SimOnPanw left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@SimOnPanw SimOnPanw merged commit 9429eda into main Nov 14, 2025
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants