logoalt Hacker News

jbergstroemyesterday at 8:44 AM1 replyview on HN

Another (more complete? maintenance, security checks) solution is to allow renovatebot handle this for you. Enable this preset: https://docs.renovatebot.com/presets-helpers/#helperspingith...

..and in the next update cycle, you will see all actions be pinned like this:

- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6


Replies

JackSlateuryesterday at 9:23 AM

This only handle your actions, not their dependencies (which seems to be the purpose of gh-actions-lockfile)