Skip to content

chore(ci): bump the secure-runner pin - #25

Closed
decofe wants to merge 1 commit into
mainfrom
centaur/bump-secure-runner-pin-20260922
Closed

decofe wants to merge 1 commit into
mainfrom
centaur/bump-secure-runner-pin-20260922

Conversation

@decofe

@decofe decofe commented Sep 22, 2026

Copy link
Copy Markdown
Member

Bump only the secure-runner reference in the shared deny workflow to tempoxyz/gh-actions commit 7e2ea6e1a8f5a22f16c2d4b389ffde25da93fa1b, published as 2026-09-22T22-21-59Z-7e2ea6e1. Keep the cargo-deny action, toolchain installer, inputs, permissions, and job behavior unchanged.

Prompted by: @DaniPopes

Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
This was referenced Sep 22, 2026
decofe added a commit to alloy-rs/chains that referenced this pull request Sep 23, 2026
Replace the inline cargo-deny setup with a pinned call to
`tempoxyz/ci/.github/workflows/deny.yml`, keeping the job ID,
permissions, toolchain, deny flags, and trigger conditions. The shared
workflow retains its vendored cargo-deny action and existing inputs.

Prompted by: @DaniPopes

Pin direct Secure Runner calls to
`7e2ea6e1a8f5a22f16c2d4b389ffde25da93fa1b`
(`2026-09-22T22-21-59Z-7e2ea6e1`) and keep dependency checks delegated
to `tempoxyz/ci/.github/workflows/deny.yml`. The shared deny reference
uses `feeee35d6e4047767f0d97881ac6e83fe3c9ebf3`, whose only change is
the same Secure Runner pin update; cargo-deny and workflow inputs stay
unchanged.

Shared deny pin update:
[tempoxyz/ci#25](tempoxyz/ci#25).

---------

Co-authored-by: DaniPopes <57450786+DaniPopes@users.noreply.github.com>
decofe added a commit to paradigmxyz/solar that referenced this pull request Sep 23, 2026
Replace the inline cargo-deny setup with a pinned call to
`tempoxyz/ci/.github/workflows/deny.yml`, keeping the job ID,
permissions, toolchain, deny flags, and trigger conditions. The shared
workflow retains its vendored cargo-deny action and existing inputs.

Prompted by: @DaniPopes

Pin direct Secure Runner calls to
`7e2ea6e1a8f5a22f16c2d4b389ffde25da93fa1b`
(`2026-09-22T22-21-59Z-7e2ea6e1`) and keep dependency checks delegated
to `tempoxyz/ci/.github/workflows/deny.yml`. The shared deny reference
uses `feeee35d6e4047767f0d97881ac6e83fe3c9ebf3`, whose only change is
the same Secure Runner pin update; cargo-deny and workflow inputs stay
unchanged.

Shared deny pin update:
[tempoxyz/ci#25](tempoxyz/ci#25).

---------

Co-authored-by: DaniPopes <57450786+DaniPopes@users.noreply.github.com>
decofe added a commit to paradigmxyz/revm-inspectors that referenced this pull request Sep 23, 2026
Replace the inline cargo-deny setup with a pinned call to
`tempoxyz/ci/.github/workflows/deny.yml`, keeping the job ID,
permissions, toolchain, deny flags, and trigger conditions. The shared
workflow retains its vendored cargo-deny action and existing inputs.

This PR targets the rollout branch in
[#513](#513)
so its diff contains only the deny correction.

Prompted by: @DaniPopes

Pin direct Secure Runner calls to
`7e2ea6e1a8f5a22f16c2d4b389ffde25da93fa1b`
(`2026-09-22T22-21-59Z-7e2ea6e1`) and keep dependency checks delegated
to `tempoxyz/ci/.github/workflows/deny.yml`. The shared deny reference
uses `feeee35d6e4047767f0d97881ac6e83fe3c9ebf3`, whose only change is
the same Secure Runner pin update; cargo-deny and workflow inputs stay
unchanged.

Shared deny pin update:
[tempoxyz/ci#25](tempoxyz/ci#25).

---------

Co-authored-by: DaniPopes <57450786+DaniPopes@users.noreply.github.com>
decofe added a commit to alloy-rs/evm2 that referenced this pull request Sep 23, 2026
Replace the inline cargo-deny setup with a pinned call to
`tempoxyz/ci/.github/workflows/deny.yml`, keeping the job ID,
permissions, toolchain, deny flags, and trigger conditions. The shared
workflow retains its vendored cargo-deny action and existing inputs.

Prompted by: @DaniPopes

Pin direct Secure Runner calls to
`7e2ea6e1a8f5a22f16c2d4b389ffde25da93fa1b`
(`2026-09-22T22-21-59Z-7e2ea6e1`) and keep dependency checks delegated
to `tempoxyz/ci/.github/workflows/deny.yml`. The shared deny reference
uses `feeee35d6e4047767f0d97881ac6e83fe3c9ebf3`, whose only change is
the same Secure Runner pin update; cargo-deny and workflow inputs stay
unchanged.

Shared deny pin update:
[tempoxyz/ci#25](tempoxyz/ci#25).

---------

Co-authored-by: DaniPopes <57450786+DaniPopes@users.noreply.github.com>
@decofe decofe closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants