Pin dependencies#221
Conversation
SummaryThis Renovate-generated PR pins seven SonarSource GitHub Actions to specific versions across the repository's CI/CD workflows. The changes move from floating version tags (e.g., The pinning affects 11 workflow files and one custom action, with multiple references in some files like What reviewers should knowWhat to verify:
Where to look:
No functional changes: Workflows should continue to behave identically; this is purely about version pinning strategy.
|
There was a problem hiding this comment.
LGTM! ✅
Clean dependency-pinning PR with no functional changes. All 7 targeted SonarSource action families are pinned consistently and correctly across the 11 affected files. Non-SonarSource actions (actions/*, jdx/mise-action, etc.) are already pinned to commit SHAs throughout the repo.
One gap worth noting: five workflows that this PR touches also reference sonarsource/gh-action-lt-backlog sub-actions (PullRequestClosed, PullRequestCreated, RequestReview, SubmitReview, ToggleLockBranch) still at the floating @v2 tag. Renovate apparently isn't configured to manage this action family. It's not a blocker for merging this PR, but worth adding to Renovate's config or pinning manually to keep the posture consistent.
|





This PR contains the following updates:
v1→1.3.34v1→v1.4.4v6→6.8.0v1→v1.0.7v1→1.5.4v1→1.0.0v3→3.4.0Add the preset
:preserveSemverRangesto your config if you don't want to pin your dependencies.Configuration
📅 Schedule: (in timezone CET)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.