Skip to content

Conversation

avivkeller
Copy link

This PR hardens the CI by explicitly pinning all GitHub actions to their exact commit SHAs. Additionally, it enables Dependabot for future upgrades + security alerts.

@avivkeller avivkeller requested a review from a team as a code owner July 31, 2025 12:59
@avivkeller
Copy link
Author

Note on the required checks:

  • Using paths: based workflow is best-practice (since it involves less bash script), but it would require removing enforce-review-rules. I can revert if needed
  • test (18.x, ubuntu-latest) should be renamed Test / Foundry project

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant