update github actions to target specific versions #71
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Problem Description
GitHub workflow actions targeted major versions only instead of targeting specific releases. This is a security concern as the latest minor/patch versions could be compromised.
Solution
Target specific versions. I did not target hashes as all of the actions are from the GitHub Actions organization. For other owners I think we'd want to target commit hashes.
Added dependabot weekly task for updating the actions.
how you tested the change
Will test on this PR.
Where the following done: