Skip to content

chore: pin all GitHub Actions to commit SHAs - #420

Closed
KooshaPari wants to merge 21 commits into
mainfrom
chore/pin-github-actions-20260430
Closed

chore: pin all GitHub Actions to commit SHAs#420
KooshaPari wants to merge 21 commits into
mainfrom
chore/pin-github-actions-20260430

fix(governance): rewrite CLAUDE.md — was incorrectly labeled TypeScri…

8a22fc7
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded May 1, 2026 in 4s

3 new alerts including 3 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 3 medium

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 8 in .github/workflows/doc-links.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 8 in .github/workflows/fr-coverage.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 9 in .github/workflows/quality-gate.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}