apache / apache/airavata-custos
Introduce automation to keep `pnpm/action-setup` up-to-date
- Dominant language
- Go
- Stars
- 21
- Forks
- 39
- Avg merge
- 2d 18h
- Merged PRs (30d)
- 6
Description
Hello! This issue was created semi-automatically because this repo popped up in a search. Per https://infra.apache.org/github-actions-policy.html, 3rd-party actions such as `pnpm/action-setup` must be referred to by hash and kept up-to-date by automation such as dependabot. It looks like this repo does not pollow this policy yet.
We plan to start enforcing this policy for `pnpm/action-setup` through https://github.com/apache/infrastructure-actions/pull/1193 .
If this was a false posivite, you can close this issue. Otherwise, you likely want to update your workflows, since they will stop working once that PR is merged.
Contributor guide
Research direction
Locate the repository's GitHub Actions workflow files and check how pnpm/action-setup is referenced. Update that action to the required commit hash and add or adjust automation for keeping it current; done means the workflows comply with the Apache policy and continue to work.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, security
- Issue type
- Feature
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 68/100