Skip to content

Conversation

@MariusStorhaug
Copy link
Member

All GitHub Actions are now pinned to specific SHA versions for improved security and consistency. The dependabot configuration has been updated to use daily checks with a 7-day cooldown period.

Pin action versions to SHA

The following actions have been pinned to specific SHA versions:

  • actions/checkout8e8c483db84b4bee98b60c0593521ed34d9990e8 (v6.0.1)
  • PSModule/GitHub-Script2010983167dc7a41bcd84cb88e698ec18eccb7ca (v1.7.8)
  • PSModule/Process-PSModulebe7d5dcbceec14855d325fdd34f2a7c2f05a7f57 (v5.4.1)

Fix dependabot configuration

The dependabot.yml has been updated to align with the standard configuration:

  • Changed schedule.interval from weekly to daily
  • Added cooldown.default-days: 7 to delay updates for 7 days after release

This ensures Dependabot checks for updates daily but waits 7 days before creating PRs, giving time for any issues with new releases to surface.

@MariusStorhaug MariusStorhaug marked this pull request as ready for review January 22, 2026 17:04
Copilot AI review requested due to automatic review settings January 22, 2026 17:05
@MariusStorhaug MariusStorhaug self-assigned this Jan 22, 2026
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request enhances security by pinning GitHub Actions to specific SHA versions and updates the dependabot configuration to use daily checks. However, there is a critical issue with an invalid configuration field in the dependabot.yml file.

Changes:

  • Pinned actions/checkout, PSModule/GitHub-Script, and PSModule/Process-PSModule to SHA versions with version comments
  • Changed dependabot schedule from weekly to daily
  • Added cooldown configuration (invalid field)

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
.github/workflows/Update-FontsData.yml Pinned actions/checkout to v6.0.1 SHA and PSModule/GitHub-Script to v1.7.8 SHA
.github/workflows/Process-PSModule.yml Pinned PSModule/Process-PSModule workflow reference to v5.4.1 SHA
.github/dependabot.yml Changed schedule to daily and added invalid cooldown configuration

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@MariusStorhaug MariusStorhaug merged commit d9fa9ef into main Jan 22, 2026
45 checks passed
@MariusStorhaug MariusStorhaug deleted the patch/pin-action-versions-and-fix-dependabot branch January 22, 2026 17:08
@github-actions
Copy link
Contributor

Module GoogleFonts - 1.0.99 published to the PowerShell Gallery.

@github-actions
Copy link
Contributor

GitHub release for GoogleFonts v1.0.99 has been created.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Patch]: Pin action versions and fix dependabot settings

2 participants