⚙️ [Maintenance]: Workflow reference pinned to immutable SHA#575
Merged
Marius Storhaug (MariusStorhaug) merged 1 commit intomainfrom Apr 4, 2026
Merged
Conversation
Contributor
No Significant Changes DetectedThis PR does not contain changes to files that would trigger a new release:
Build, test, and publish stages will be skipped for this PR. If you believe this is incorrect, please verify that your changes are in the correct locations. |
Copilot started reviewing on behalf of
Marius Storhaug (MariusStorhaug)
April 4, 2026 23:03
View session
Contributor
There was a problem hiding this comment.
Pull request overview
Pins the repository’s Process-PSModule reusable workflow reference to an immutable commit SHA to align with the existing security hardening pattern for GitHub Actions uses: references and enable safe Dependabot updates.
Changes:
- Updated
.github/workflows/Process-PSModule.ymlto replace the mutable@v5tag with a full commit SHA. - Added a trailing comment to preserve the human-readable patch version (
# v5.4.5).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The CI workflow reference is now pinned to a specific commit SHA, consistent with all other
uses:references in the PSModule infrastructure. Dependabot will automatically propose updates when new versions of Process-PSModule are released.Changed: Workflow reference pinned to immutable SHA
The
Process-PSModulereusable workflow reference in.github/workflows/Process-PSModule.ymlwas using a mutable major version tag (@v5). It is now pinned to the exact commit SHA with the patch-level version in a trailing comment:Dependabot's
github-actionsecosystem is already configured and will keep this reference up to date automatically.Technical Details
@v5to@4343d76f9e8c9468527175ea292092c2d055be8c # v5.4.5in.github/workflows/Process-PSModule.yml.dependabot.ymlalready coversgithub-actionsin/, so SHA-pinned reusable workflow references will be updated automatically.v5currently resolves to the same commit (4343d76).