Introduce automation to keep `pnpm/action-setup` up-to-date
- Dominant language
- Java
- Stars
- 7.4k
- Forks
- 1.3k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 32
Description
Hello! This issue was created semi-automatically because this repo popped up in a search. Per https://infra.apache.org/github-actions-policy.html, 3rd-party actions such as `pnpm/action-setup` must be referred to by hash and kept up-to-date by automation such as dependabot. It looks like this repo does not pollow this policy yet.
We plan to start enforcing this policy for `pnpm/action-setup` through https://github.com/apache/infrastructure-actions/pull/1193 .
If this was a false posivite, you can close this issue. Otherwise, you likely want to update your workflows, since they will stop working once that PR is merged.
Contributor guide
Research direction
Start by inspecting the repository's GitHub Actions workflow files for references to pnpm/action-setup, then read the Apache GitHub Actions policy and the linked infrastructure-actions enforcement context. Done means relevant action references use commit hashes and can be kept current by automation before the policy is enforced.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd
- Issue type
- Feature
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 68/100