Skip to content

chore(ci): bump socket-registry action refs#1174

Open
jdalton wants to merge 2 commits intomainfrom
chore/bump-socket-registry-refs
Open

chore(ci): bump socket-registry action refs#1174
jdalton wants to merge 2 commits intomainfrom
chore/bump-socket-registry-refs

Conversation

@jdalton
Copy link
Copy Markdown
Contributor

@jdalton jdalton commented Apr 7, 2026

Summary

  • Bumps all SocketDev/socket-registry SHA refs to 8d54162f37b88ef2970a892b6c619b7c064f0c23 (install, setup-git-signing, cleanup-git-signing actions)
  • Covers ci.yml, provenance.yml, and weekly-update.yml

Bumps socket-registry SHA refs to include inline zizmor security audit.


Note

Medium Risk
Updates pinned SHAs for third-party GitHub Actions used across CI/publish workflows; while behavior should be unchanged, any upstream action change can affect build/release reliability and supply-chain posture.

Overview
Bumps all SocketDev/socket-registry GitHub Action pins to commit 8d54162f37b88ef2970a892b6c619b7c064f0c23 across the CI workflows.

This updates the install action in ci.yml and provenance.yml, and updates install, setup-git-signing, and cleanup-git-signing in weekly-update.yml.

Reviewed by Cursor Bugbot for commit 8ecb5e9. Configure here.

@jdalton jdalton enabled auto-merge (squash) April 7, 2026 20:29
@jdalton jdalton force-pushed the chore/bump-socket-registry-refs branch 3 times, most recently from 3300846 to 881f666 Compare April 8, 2026 02:39
@jdalton jdalton force-pushed the chore/bump-socket-registry-refs branch from 881f666 to 04c42a2 Compare April 8, 2026 02:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant