ci(workflows): pin GitHub Actions dependencies to commit SHAs#401
ci(workflows): pin GitHub Actions dependencies to commit SHAs#401
Conversation
Pin all third-party GitHub Actions to their full commit SHA instead of mutable version tags. This is a supply-chain security best practice that prevents tag-mutation attacks. Changed files: spellcheck.yml Total actions pinned: 2 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Warning Rate limit exceeded
⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Pin all third-party GitHub Actions to their full commit SHA for supply-chain security.
Changes
Changed Files
.github/workflows/spellcheck.ymlTesting
@refportion ofuses:directives is modifiedMemory / Performance Impact
N/A - CI configuration only.
Related Issues
Closes #400