Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

✅ Fix GH action for rubygems Trusted Publishing (backport: #340) #341

Merged
merged 2 commits into from
Oct 13, 2024

Conversation

nevans
Copy link
Collaborator

@nevans nevans commented Oct 13, 2024

This backports #340 from master (v0.5.0-dev).

I'm not sure why dependabot didn't suggest upgrading these.  But we need
to consider these actions as trustworthy, so I think that any security
risk due to using a version branch (rather than a checksum) is offset by
the hassle (and security risk!) of not automatically getting updates.

In particular, even if dependabot _did_ make PRs to upgrade these, it
wouldn't have made a PR for the `v0.4-stable` branch.
This upgrade was handled on the main branch by dependabot.
@nevans nevans merged commit 8484205 into v0.4-stable Oct 13, 2024
26 checks passed
@nevans nevans deleted the backport/0.4/340/fix-gh-workflow-push_gem branch October 13, 2024 19:23
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

1 participant