From c9c5530f609c36725438cae2c2581d21e6c325fc Mon Sep 17 00:00:00 2001 From: clawbot Date: Fri, 20 Feb 2026 03:10:39 -0800 Subject: [PATCH] security: pin all go install refs to commit SHAs --- .gitea/workflows/check.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.gitea/workflows/check.yml b/.gitea/workflows/check.yml index 4a6ed2d..5e9dd05 100644 --- a/.gitea/workflows/check.yml +++ b/.gitea/workflows/check.yml @@ -17,10 +17,10 @@ jobs: go-version-file: go.mod - name: Install golangci-lint - run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.10.1 + run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@5d1e709b7be35cb2025444e19de266b056b7b7ee # v2.10.1 - name: Install goimports - run: go install golang.org/x/tools/cmd/goimports@latest + run: go install golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0 # v0.42.0 - name: Run make check run: make check