Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
I was going to open an issue for this, but I thought I could just open a PR to discuss it.
Pinning full commit SHAs is best practice for security. We recently did this in the Android repos and
I noticed that some of our workflows come from this repo.
Dependabot should also open PRs for this and update both the SHA and the comment, see this issue
Docs: https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions
Automatically pinned with https://github.com/mheap/pin-github-action and then cleaned up manually.