Skip to content

Get rid of dependencies #146

@ytterx

Description

@ytterx

As far as I can see this GitHub action depends on two dependencies that are not from GitHub them self or from verified users:

ilammy/msvc-dev-cmd
mamba-org/setup-micromamba

Would it be feasible to get rid of these two? As I need to whitelist certain GitHub actions due to policy, I now also need to whitelist these, but versions are for example not pinned down to specific patch versions. (See recent news on npm phishing and packaging issues)

At the minimum, versions should probably be pinned more specific, and maybe mamba-org/setup-micromamba@v1 should be upgraded to v2?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions