Skip to content

[SECENG-364] Pin GitHub Actions to commit SHAs#6

Draft
Stephanie Ginovker (sginovker) wants to merge 1 commit intomainfrom
security/pin-actions-to-sha
Draft

[SECENG-364] Pin GitHub Actions to commit SHAs#6
Stephanie Ginovker (sginovker) wants to merge 1 commit intomainfrom
security/pin-actions-to-sha

Conversation

@sginovker
Copy link
Copy Markdown

@sginovker Stephanie Ginovker (sginovker) commented May 7, 2026

Ticket

SECENG-364

Summary

Dependabot

Added/updated dependabot.yml to keep GitHub Actions pinned to the latest SHA with a 7-day update cooldown. hoverinc/* is excluded from the cooldown so internal actions can auto-merge promptly.

PR Automation

Added .github/workflows/pr-automation.yml calling hoverinc/action-pr-automation to auto-merge safe dependabot PRs (dev deps and approved production deps).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant