Skip to content

chore: pin GitHub Actions to commit SHAs#62

Open
bhimrazy wants to merge 1 commit into
Lightning-AI:mainfrom
bhimrazy:chore/pin-workflow-actions
Open

chore: pin GitHub Actions to commit SHAs#62
bhimrazy wants to merge 1 commit into
Lightning-AI:mainfrom
bhimrazy:chore/pin-workflow-actions

Conversation

@bhimrazy

@bhimrazy bhimrazy commented Jun 4, 2026

Copy link
Copy Markdown

What does this PR do?

Pins GitHub Actions and reusable workflows to verified commit SHAs for supply chain security.

This follows the same pattern as Lightning-AI/pytorch-lightning#21735.

Pinned references

Action / workflow Release Commit SHA
actions/checkout v6.0.2 de0fac2e4500dabe0009e67214ff5f5447ce83dd
actions/setup-python v6.2.0 a309ff8b426b58ec0e2a45f0f869d46889d02405
astral-sh/setup-uv v7.6.0 37802adc94f370d6bfd71619e3f0bf239e1f3b78
actions/upload-artifact v7.0.1 043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
pypa/gh-action-pypi-publish v1.13.0 ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e
AButler/upload-release-assets v3.0 3d6774fae0ed91407dc5ae29d576b166536d1777
Lightning-AI/utilities v0.15.3 86fe1b20b4609835ba9e8c8739cd39707ba76868

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants