For supply-chain security, we should pin the GitHub Actions referenced in the workflows to their commit SHAs. Dependabot can be used to automatically update these commit SHAs with a specified cooldown period.
See example at microsoft/dotnet-framework-docker#1317
For supply-chain security, we should pin the GitHub Actions referenced in the workflows to their commit SHAs. Dependabot can be used to automatically update these commit SHAs with a specified cooldown period.
See example at microsoft/dotnet-framework-docker#1317