Skip to content

Pin gocovmerge#1082

Open
cpuguy83 wants to merge 1 commit into
project-dalec:mainfrom
cpuguy83:pin_gocovmerge
Open

Pin gocovmerge#1082
cpuguy83 wants to merge 1 commit into
project-dalec:mainfrom
cpuguy83:pin_gocovmerge

Conversation

@cpuguy83

@cpuguy83 cpuguy83 commented Jun 7, 2026

Copy link
Copy Markdown
Collaborator

This hasn't changed in 10 years, but good to pin so a malicious or breaking commit doesn't cause us headache.

This hasn't changed in 10 years, but good to pin so a malicious or
breaking commit doesn't cause us headache.

Signed-off-by: Brian Goff <cpuguy83@gmail.com>
Copilot AI review requested due to automatic review settings June 7, 2026 17:30

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR pins the gocovmerge Go tool installation in CI to a specific commit SHA instead of using @latest, preventing potential supply chain attacks or breaking changes from affecting the CI pipeline. This aligns with the existing practice in the workflow where all GitHub Actions are already pinned to specific commit hashes.

Changes:

  • Pin gocovmerge from @latest to commit b5bfa59ec0adc420475f97f89b58045c721d761c (the HEAD of the repository, last updated in 2016)

@cpuguy83 cpuguy83 self-assigned this Jun 7, 2026
@cpuguy83 cpuguy83 requested a review from kartikjoshi21 June 7, 2026 17:39
@cpuguy83 cpuguy83 requested a review from invidian June 15, 2026 23:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants