Skip to content

Conversation

@lwasser
Copy link
Member

@lwasser lwasser commented Oct 8, 2025

closes #531

What:
This adds hashes to gh actions for increased security.

Why:

How:

I'll setup dependabot next

Checklist:

  • Documentation
  • Ready to be merged
  • Added myself to contributors table.

@vercel
Copy link

vercel bot commented Oct 8, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
app Error Error Oct 8, 2025 1:30am

@lwasser
Copy link
Member Author

lwasser commented Oct 8, 2025

@all-contributors please add @lwasser for infra

@allcontributors
Copy link
Contributor

@lwasser

I've put up a pull request to add @lwasser! 🎉

@lwasser
Copy link
Member Author

lwasser commented Oct 8, 2025

@JoshuaKGoldberg we've been working on a review approach where one of of reviews the others' pr's before merging! So if you are open to that, please review this one!! 🚀

I think we will have to look at tests separately and merge this without tests passing. But i do want to get tests working before we consider any sort of deployment.

I'm going to look at the Dependabot settings next.

lwasser pushed a commit that referenced this pull request Oct 8, 2025
Adds @lwasser as a contributor for infra.

This was requested by lwasser [in this
comment](#532 (comment))

[skip ci]

---------

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
Copy link
Contributor

@JoshuaKGoldberg JoshuaKGoldberg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒

@JoshuaKGoldberg JoshuaKGoldberg merged commit 6a9aa68 into main Oct 9, 2025
2 of 4 checks passed
@JoshuaKGoldberg JoshuaKGoldberg deleted the harden-actions branch October 9, 2025 11:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore: harden CI actions using hashes and setup dependabot to auto update in the future

3 participants