Skip to content

Harden CI supply chain settings#49

Draft
k-asm wants to merge 2 commits into
fix/deprecate-xref-excludefrom
chore/supply-chain-hardening-stacked
Draft

Harden CI supply chain settings#49
k-asm wants to merge 2 commits into
fix/deprecate-xref-excludefrom
chore/supply-chain-hardening-stacked

Conversation

@k-asm
Copy link
Copy Markdown
Collaborator

@k-asm k-asm commented May 24, 2026

Changes

  • Pin actions/checkout and erlef/setup-beam to commit SHAs.
  • Update actions/checkout to v6.0.2.
  • Restrict the workflow GITHUB_TOKEN to contents: read.
  • Fetch only test dependencies with mix deps.get --check-locked --only test.
  • Tighten the dev-only ex_doc requirement to ~> 0.34.

Stacked on #48. No new workflows or CI jobs are added.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant