Introduce automation to keep `pnpm/action-setup` up-to-date
- Dominant language
- Java
- Stars
- 1.1k
- Forks
- 456
- PR merge metrics
- No merged PRs in 30d
Description
Hello! This issue was created semi-automatically because this repo popped up in a search. Per https://infra.apache.org/github-actions-policy.html, 3rd-party actions such as `pnpm/action-setup` must be referred to by hash and kept up-to-date by automation such as dependabot. It looks like this repo does not pollow this policy yet.
We plan to start enforcing this policy for `pnpm/action-setup` through https://github.com/apache/infrastructure-actions/pull/1193 .
If this was a false posivite, you can close this issue. Otherwise, you likely want to update your workflows, since they will stop working once that PR is merged.
Contributor guide
Research direction
Start by inspecting the repository's GitHub Actions workflow files and compare their pnpm/action-setup references with the Apache GitHub Actions policy. Review the linked infrastructure-actions pull request for the expected enforcement, then confirm that the workflows use hash-pinned references and that automation will keep them current.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd
- Issue type
- Feature
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 68/100