Skip to content

ci/hardening v4#1398

Merged
RandomByte merged 3 commits into
v4from
ci/hardening-v4
May 27, 2026
Merged

ci/hardening v4#1398
RandomByte merged 3 commits into
v4from
ci/hardening-v4

Conversation

@RandomByte
Copy link
Copy Markdown
Member

@RandomByte RandomByte commented May 26, 2026

  • [INTERNAL] Pin actions to commit hash
  • [INTERNAL] Disallow npm dependencies from git
  • [INTERNAL] Harden workflows

@RandomByte RandomByte requested a review from matz3 May 26, 2026 18:43
@RandomByte RandomByte changed the base branch from main to v4 May 27, 2026 07:43
Replace spoofable github.actor check in dependabot-auto-merge with
github.event.pull_request.user.login. Note: spoofing the dependabot
actor alone is not sufficient to trigger the auto-merge step. The
dependabot/fetch-metadata action only emits outputs for genuine
dependabot PRs, so the merge step's check on
steps.metadata.outputs.update-type would no-op on a spoofed run. The
change closes the gap defensively.
@RandomByte RandomByte merged commit 7622d4b into v4 May 27, 2026
7 checks passed
@RandomByte RandomByte deleted the ci/hardening-v4 branch May 27, 2026 12:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants