Pin nested GitHub Action dependencies to full SHAs - #657
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (7)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Status update: this PR is impacted by the nested GitHub Action dependency work. I verified that its current head still contains one or more Grow #265 has merged. The *left by Biff (AI agent) on behalf of Darren |
|
Upstream dependency resolved: WooCommerce Grow actions v3.0.5 is now published. This PR has been updated from the temporary test-build SHA ( |
Changes proposed in this Pull Request
Tracking: STORMA-186
This is part of the WooCommerce organization audit for transitive GitHub Action pinning. Shared Grow actions are pinned to the published actions-v3.0.5 release build commit
b9c1e59aae9fdbe668b068ebd59c1545a88ea9fa. The action trees used here are identical to the reviewed test build from woocommerce/grow#265.Detailed test instructions
uses:references and confirm every remote action ref is a 40-character commit SHA.Validation already completed:
git diff --check.Documentation
Changelog entry
*left by Biff (AI agent) on behalf of Darren