Repository navigation
ci: pin actions to SHAs and untrack local Claude settings - #4
Conversation
Every `uses:` now names a full commit with the release in a comment, so a moved tag cannot change what runs here; Dependabot keeps the pins current with a seven-day cooldown. `persist-credentials: false` on the checkouts in ci.yml, matching commitlint.yml. zizmor reports nothing. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HYsh5vYW7fVEvRFTRiJ4h8
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HYsh5vYW7fVEvRFTRiJ4h8
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (5)
💤 Files with no reviewable changes (1)
Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📝 WalkthroughWalkthroughThe pull request pins GitHub Actions to commit SHAs, disables checkout credential persistence in CI, adds Dependabot cooldowns, and removes and ignores local Claude settings. ChangesAutomation and local configuration hardening
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The hardening changes do not introduce an identified workflow or repository-hygiene risk and are ready to merge. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
A rabbit reads each line, Comment |
Two of the pre-public items from #1's checklist.
Actions pinned to commit SHAs.
actions/checkout(v7.0.1),actions/cache(v6.1.0) andwagoid/commitlint-github-action(v6.2.1), each with the release in a trailing comment so Dependabot can bump them. The checkout and cache majors move from v4, which also clears the Node 20 deprecation warning on every run.persist-credentials: falseon the three checkouts inci.yml;commitlint.ymlalready had it. Dependabot gets a seven-day cooldown for both ecosystems.zizmor .github/workflowsreports no findings..claude/settings.local.jsonuntracked and ignored: it is a per-developer permissions file.Once this merges, the repo setting Require actions to be pinned to a full-length commit SHA can be turned on without breaking CI.
🤖 Generated with Claude Code
https://claude.ai/code/session_01HYsh5vYW7fVEvRFTRiJ4h8
Summary by CodeRabbit
Chores
Impact