From f0a15caea1fd0cc96743fb28540766db45cae521 Mon Sep 17 00:00:00 2001 From: Kentaro Hayashi Date: Fri, 27 Mar 2026 15:00:25 +0900 Subject: [PATCH] ci: use sha pinning to mitigate Lower risk about supply chain attack even though matched tag was compromised. Signed-off-by: Kentaro Hayashi --- .github/workflows/test.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 1cd4bd8..69ab996 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -25,8 +25,8 @@ jobs: - ubuntu-latest name: Ruby ${{ matrix.ruby }} ${{ matrix.os }} steps: - - uses: actions/checkout@v6 - - uses: ruby/setup-ruby@v1 + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + - uses: ruby/setup-ruby@4dc28cf14d77b0afa6832d9765ac422dbf0dfedd # v1.298.0 with: ruby-version: ${{ matrix.ruby }} - name: unit testing