GH-49727: [CI] Pin GitHub Actions to commit SHAs instead of tags#49735
GH-49727: [CI] Pin GitHub Actions to commit SHAs instead of tags#49735thisisnic wants to merge 1 commit intoapache:mainfrom
Conversation
|
|
|
I believe that these failures are expected:
|
raulcd
left a comment
There was a problem hiding this comment.
We did stop pinning hash specifically for those due to the policy not requiring pinning sha for non external actions, see:
#48327
@kou what are your thoughts on this?
@kevinjqliu do you have any insight on whether this should specify hash or not? I see that iceberg-python move to specify a hash (apache/iceberg-python#3194)
but based on policy: https://infra.apache.org/github-actions-policy.html the actions/checkout is not strictly required.
I don't want to merge this and remove it in 6 months, I'd rather push for a change of policy and require pinning for all.
I want to use But we need to pin SHA for other actions such as How about pinning only other actions? |
Rationale for this change
GHA pinned to tags (movable) not SHAs (unique)
What changes are included in this PR?
Ping to SHAs
Are these changes tested?
CI will run
Are there any user-facing changes?
No