Skip to content

Hash pin GitHub Actions#9568

Merged
hugovk merged 1 commit intopython-pillow:mainfrom
hugovk:pin-gha
Apr 17, 2026
Merged

Hash pin GitHub Actions#9568
hugovk merged 1 commit intopython-pillow:mainfrom
hugovk:pin-gha

Conversation

@hugovk
Copy link
Copy Markdown
Member

@hugovk hugovk commented Apr 17, 2026

Done using https://github.com/suzuki-shunsuke/pinact, which did all except for the fuzzers:

pinact run
ERROR failed to handle a line: action can't be pinned
.github/workflows/cifuzz.yml:38
      uses: google/oss-fuzz/infra/cifuzz/actions/build_fuzzers@master
ERROR failed to handle a line: action can't be pinned
.github/workflows/cifuzz.yml:45
      uses: google/oss-fuzz/infra/cifuzz/actions/run_fuzzers@master

Shall we pin them to the latest 4c0e105abd10caa29391edb4a0fad3db25eeade4?

@hugovk hugovk added the changelog: skip Exclude PR from release draft label Apr 17, 2026
@radarhere
Copy link
Copy Markdown
Member

Shall we pin them to the latest 4c0e105abd10caa29391edb4a0fad3db25eeade4?

Sounds good to me.

@hugovk
Copy link
Copy Markdown
Member Author

hugovk commented Apr 17, 2026

They just made a new commit on https://github.com/google/oss-fuzz/commit so I put that one :)

We also don't need the Zizmor unpinned-uses exception any more.

@hugovk hugovk merged commit 087376d into python-pillow:main Apr 17, 2026
74 checks passed
@hugovk hugovk deleted the pin-gha branch April 17, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

changelog: skip Exclude PR from release draft

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants