From 51f474aefdfbaefc099bca9f4a92ff38b80838e1 Mon Sep 17 00:00:00 2001 From: "aikido-autofix[bot]" <119856028+aikido-autofix[bot]@users.noreply.github.com> Date: Mon, 23 Mar 2026 22:12:33 +0000 Subject: [PATCH] fix(security): autofix 3rd party Github Actions should be pinned --- .github/workflows/rust.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/rust.yml b/.github/workflows/rust.yml index 4aab9cee7f..2924328d08 100644 --- a/.github/workflows/rust.yml +++ b/.github/workflows/rust.yml @@ -61,7 +61,7 @@ jobs: with: rust-version: ${{ matrix.rust }} - name: Install Tarpaulin - uses: actions-rs/install@v0.1 + uses: actions-rs/install@9da1d2adcfe5e7c16992e8242ca33a56b6d9b101 # v0.1 with: crate: cargo-tarpaulin version: 0.14.2 @@ -87,7 +87,7 @@ jobs: - name: Coverage run: cargo tarpaulin -o Lcov --output-dir ./coverage - name: Coveralls - uses: coverallsapp/github-action@master + uses: coverallsapp/github-action@09b709cf6a16e30b0808ba050c7a6e8a5ef13f8d # master with: github-token: ${{ secrets.GITHUB_TOKEN }}