Introduce automation to keep `pnpm/action-setup` up-to-date
- Dominant language
- Java
- Stars
- 30
- Forks
- 9
- Avg merge
- 27m
- Merged PRs (30d)
- 1
Description
Hello! This issue was created semi-automatically because this repo popped up in a search. Per https://infra.apache.org/github-actions-policy.html, 3rd-party actions such as `pnpm/action-setup` must be referred to by hash and kept up-to-date by automation such as dependabot. It looks like this repo doesn't pollow this policy yet. We plan to start enforcing this policy for pnpm/action-setup through https://github.com/apache/infrastructure-actions/pull/1193 . If this was a false posivite, you can close this issue. Otherwise, you likely want to update your workflows, since they will stop working once that PR is merged.
Contributor guide
No contributing guide indexed for this repository
Research direction
Inspect the repository's GitHub Actions workflows and Dependabot configuration first; the issue does not name specific files. Verify where pnpm/action-setup is referenced, pin it by hash, and configure automation to keep that reference current, then confirm the workflows remain valid.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd
- Issue type
- Feature
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 70/100