Skip to content

Add helpers:pinGitHubActionDigests to org-wide Renovate config - #86

Merged
jsmid1 merged 1 commit into
conforma:mainfrom
jsmid1:EC-2080
Aug 26, 2026
Merged

Add helpers:pinGitHubActionDigests to org-wide Renovate config#86
jsmid1 merged 1 commit into
conforma:mainfrom
jsmid1:EC-2080

Conversation

@jsmid1

@jsmid1 jsmid1 commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adds helpers:pinGitHubActionDigests preset to the shared org-wide Renovate config
  • This ensures all conforma repos get automatic GitHub Action SHA pinning for security
  • Previously only configured locally in conforma/cli (via EC-2045)

Context

Stefano suggested promoting this org-wide since it's relevant to all repos (feedback on cli#3463).

A follow-up PR in conforma/cli removes the now-redundant local override.

Impact

~20 repos will each get 1 grouped Renovate PR pinning their unpinned GitHub Actions (mostly conforma/pr-size-label-action and conforma/github-workflows refs). One-time burst, then steady-state.

Resolves: EC-2080

Pin GitHub Actions to SHA digests across all conforma repos for
security. Previously only configured in conforma/cli locally.

Resolves: EC-2080

Co-authored-by: Claude <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8fd551ae-dbce-46e8-82dd-fd12ec69b776


Comment @coderabbitai help to get the list of available commands.

@robnester-rh robnester-rh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jsmid1
jsmid1 merged commit 5a82e6d into conforma:main Aug 26, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants