Skip to content

Conversation

@bioball
Copy link
Member

@bioball bioball commented Dec 9, 2025

This adopts the version locking introduced in [email protected].

@StefMa
Copy link
Contributor

StefMa commented Dec 10, 2025

😱 How have to done that? 🤔 How does version locking works?

@HT154
Copy link
Contributor

HT154 commented Dec 10, 2025

😱 How have to done that? 🤔 How does version locking works?

The implementation is in apple/pkl-project-commons#44 but the plan is to ship this in pkl-pantry once we've got it dialed in. The idea here is to use a fake workflow to maintain the version pinning in a format that dependabot can automatically open PRs to update. This allows users of com.github.actions to pin actions to specific SHAs without needing to manually update them, maintaining parity with direct YAML GHA usage.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants