🚀 Feature: Disable pinDigests for Renovate #1897
Labels
status: accepting prs
Please, send a pull request to resolve this!
type: feature
New enhancement or request
Bug Report Checklist
main
branch of the repository.Overview
Following #1894 & #1895: I don't want GHA digests to be pinned. It's annoying and I want to stick with semver.
Additional Info
I understand the value in preserving commit hashes. It's good for security to ensure they can't be tampered with; it prevents accidental changes over time; etc. - https://docs.renovatebot.com/docker.
But I don't find those arguments persuasive enough to turn on these updates by default in all CTA repos. A big point of CTA is to make friendly, readable config files. Big ole hashes in GHA files is not that.
💖
The text was updated successfully, but these errors were encountered: