dependabot[bot]
|
9f9e0deafb
|
Bump docker/metadata-action from 3.6.2 to 3.7.0
Bumps [docker/metadata-action](https://github.com/docker/metadata-action) from 3.6.2 to 3.7.0.
- [Release notes](https://github.com/docker/metadata-action/releases)
- [Commits](e5622373a3...f2a13332ac )
---
updated-dependencies:
- dependency-name: docker/metadata-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2022-04-06 15:44:28 +00:00 |
|
naveensrinivasan
|
dd737bd755
|
Pin actions to a full length commit SHA
- Pinned actions by SHA https://github.com/ossf/scorecard/blob/main/docs/checks.md#pinned-dependencies
- Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions
>Pin actions to a full length commit SHA
>Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps mitigate the risk of a bad actor adding a backdoor to the action's repository, as they would need to generate a SHA-1 collision for a valid Git object payload.
https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions
|
2022-03-18 20:47:20 +00:00 |
|
Chris Lu
|
adfd79e243
|
skip arm platform
|
2021-09-29 10:52:53 -07:00 |
|
Chris Lu
|
ee143f9ae0
|
github action adds dependencies
|
2021-09-06 22:54:29 -07:00 |
|
Chris Lu
|
d5c7dbac4a
|
docker: build dev containers
|
2021-09-05 23:09:13 -07:00 |
|
Chris Lu
|
705285ec60
|
rename file
|
2021-09-05 17:02:50 -07:00 |
|