From f6b64648fb6b4e7c94d420ab154fc9aa6bf9346e Mon Sep 17 00:00:00 2001 From: Imani Manyara Date: Sat, 3 Oct 2026 04:33:51 -0400 Subject: [PATCH] Float first-party actions on their major; pin third-party to a release SHA Brings the workflow action references in line with the org rule: actions/*, github/* and docker/* float on the major tag of their latest release, and third-party actions are pinned to the commit SHA of their latest release with the version in a trailing comment. 1 reference(s): - release.yml: pypa/gh-action-pypi-publish release/v1 -> dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 Pull-request CI does not run these workflows, so the checks below cannot vouch for these references; each was reviewed by hand: - release.yml: pypa/gh-action-pypi-publish release/v1 -> dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 pypi-publish: release/v1 is the v1 branch, so v1.14.2 is the same line pinned. --- .github/workflows/release.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 79f9d18..ac699fb 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -47,7 +47,7 @@ jobs: path: dist/ - name: Publish to PyPI (trusted) - uses: pypa/gh-action-pypi-publish@release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 publish-github: needs: build