From c01222a5978d5b656af4aa99db8cf957fe291237 Mon Sep 17 00:00:00 2001 From: user Date: Fri, 20 Feb 2026 02:58:12 -0800 Subject: [PATCH] security: pin CI actions to commit SHAs --- .gitea/workflows/check.yml | 23 +++++++++++------------ 1 file changed, 11 insertions(+), 12 deletions(-) diff --git a/.gitea/workflows/check.yml b/.gitea/workflows/check.yml index b26c282..00ae7ef 100644 --- a/.gitea/workflows/check.yml +++ b/.gitea/workflows/check.yml @@ -5,18 +5,17 @@ on: pull_request: branches: [main] jobs: - check: - runs-on: ubuntu-latest - steps: - # actions/checkout v4.2.2, 2026-02-22 - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 + check: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - - uses: actions/setup-go@v5 - with: - go-version-file: go.mod + - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + with: + go-version-file: go.mod - - name: Install golangci-lint - run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.10.1 + - name: Install golangci-lint + run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.10.1 - - name: Run make check - run: make check + - name: Run make check + run: make check