Skip to content

Pin mutable dependencies#149

Merged
atanasdinov merged 6 commits intomainfrom
supply-chain-risk-scan
Apr 6, 2026
Merged

Pin mutable dependencies#149
atanasdinov merged 6 commits intomainfrom
supply-chain-risk-scan

Conversation

@atanasdinov
Copy link
Copy Markdown
Contributor

@atanasdinov atanasdinov commented Apr 6, 2026

In order to address the recent supply chain attack risks, this properly pins the versions of all mutable components to a specific SHA.

Signed-off-by: Atanas Dinov <atanas.dinov@suse.com>
Signed-off-by: Atanas Dinov <atanas.dinov@suse.com>
Signed-off-by: Atanas Dinov <atanas.dinov@suse.com>
Signed-off-by: Atanas Dinov <atanas.dinov@suse.com>
Signed-off-by: Atanas Dinov <atanas.dinov@suse.com>
Signed-off-by: Atanas Dinov <atanas.dinov@suse.com>
@atanasdinov atanasdinov merged commit 3706102 into main Apr 6, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants