fix(ci): pin all action refs to explicit SHAs (RCA #15 Phase 1) #16
Reference in New Issue
Block a user
Delete Branch "fix-15-pin-shas-molecule-ci-phase1"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
LGTM — RCA #15 Phase 1 SHA pinning in molecule-ci reusable gates. Pin-only, no logic change.
40a2b2a290to82105afddfCross-author LGTM — clean implementation.
Please review
Please review
Please review
Please review
Cross-author approval for SHA pinning PR.
LGTM — SHA-pinned action refs are the correct supply-chain hardening.
LGTM — clean SHA pinning across all workflow files. Matches RCA #15 Phase 1 supply-chain hardening. Verified each SHA is a full 40-char commit ref with preserved version comment for readability.
LGTM — second approval.
Approved — action references are pinned to explicit SHAs while preserving the documented major-version intent; CI workflow behavior remains otherwise unchanged.