From ac8ebdf23d71efc7d11d859bbfb17550a3dc8b73 Mon Sep 17 00:00:00 2001 From: Drew Hintz Date: Thu, 30 Apr 2026 23:52:24 -0500 Subject: [PATCH] Pin GitHub Actions workflow references --- .github/workflows/build-and-test.yml | 2 +- .github/workflows/release-bot.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build-and-test.yml b/.github/workflows/build-and-test.yml index 8dc3f53..e09ac0f 100644 --- a/.github/workflows/build-and-test.yml +++ b/.github/workflows/build-and-test.yml @@ -16,7 +16,7 @@ jobs: steps: - uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2 - name: Set up Ruby - uses: ruby/setup-ruby@4c56a21280b36d862b5fc31348f463d60bdc55d5 # v1 + uses: ruby/setup-ruby@c4e5b1316158f92e3d49443a9d58b31d25ac0f8f # v1 with: ruby-version: ${{ matrix.version }} diff --git a/.github/workflows/release-bot.yml b/.github/workflows/release-bot.yml index 82b35e2..afb6c33 100644 --- a/.github/workflows/release-bot.yml +++ b/.github/workflows/release-bot.yml @@ -12,7 +12,7 @@ jobs: if: startsWith(github.head_ref, 'releases/') || github.event_name == 'release' runs-on: ubuntu-latest steps: - - uses: statsig-io/statsig-publish-sdk-action@main + - uses: statsig-io/statsig-publish-sdk-action@c0740fb8a2d4813522cc09bb8c4e826bb78ce6ab # main with: kong-private-key: ${{ secrets.KONG_GH_APP_PRIVATE_KEY }} rubygems-key: ${{ secrets.KONG_RUBYGEMS_KEY }}