Skip to content

Pin the action version comments to the exact released tag#47

Merged
magicsunday merged 1 commit into
mainfrom
GH-pin-version-comments
Jun 12, 2026
Merged

Pin the action version comments to the exact released tag#47
magicsunday merged 1 commit into
mainfrom
GH-pin-version-comments

Conversation

@magicsunday

Copy link
Copy Markdown
Owner

zizmor ref-version-mismatch flagged the floating major-tag comments
(# v2, # v6) on the hash-pinned actions in ci.yml. The SHAs are
correct and immutable; only the comments pointed at moving major tags.

Repoint the comments at the exact release each SHA resolves to:

  • shivammathur/setup-php2.37.1
  • actions/checkoutv6.0.2

No behaviour change — comment-only.

@gemini-code-assist

Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@github-actions

Copy link
Copy Markdown

Thanks for your first pull request to this project! Please make sure the project's checks pass before requesting review. A maintainer will get back to you soon.

zizmor ref-version-mismatch flagged the floating major-tag comments
(# v2, # v6) on the hash-pinned actions. Point them at the immutable
release the SHA resolves to (setup-php 2.37.1, checkout v6.0.3).
@magicsunday magicsunday force-pushed the GH-pin-version-comments branch from d2d9126 to fbde85d Compare June 12, 2026 10:46
@magicsunday magicsunday merged commit fa6a905 into main Jun 12, 2026
16 checks passed
@magicsunday magicsunday deleted the GH-pin-version-comments branch June 12, 2026 10:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant