Standardize hashes and version comments in workflows #838
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Closes #837
Summary
While looking at the workflow files I noticed that some actions used versions and others used hashes. I also observed that some actions (like
actions/checkout
in several places) had incorrect version comments (claiming that hashX
wasv3.3.0
, which was incorrect).If the version comment is incorrect, Dependabot fails to update it in its PRs. This is evident in a Dependabot PR that is currently open: #836 fails to update the version comment in
scorecards-analysis.yml
.I think that I've followed the contributing guidelines, including opening an issue, linking this PR to that issue, and signing-off the git commit, but please let me know if anything needs to be addressed, or if anything in this PR needs to be addressed. Thanks!
Release Note
N/A
Documentation
N/A