feat: workflow to automatically update java format + create PR#7
feat: workflow to automatically update java format + create PR#7
Conversation
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
There was a problem hiding this comment.
LGTM - hadn't seen the 'create-pull-request' action before
I see it's on version v8.1.0 now but I've got a task to go through and mitigate supply chain risks in the repos I manage, could we use SHAs for the actions here instead of version numbers, to mitigate the risk of the actions here changing out from under us ?
The sha for create-pull-request v8.1.0 is currently c0f553fe549906ede9cf27b5156039d195d2ece0 FWIW
We may want to set up dependabot for the repo as well, and it appears that dependabot can work with commit SHAs just fine
|
@mikehardy - I've updated them all to use SHAs now 🙏 |
Uh oh!
There was an error while loading. Please reload this page.