open-swe/.github
John Kennedy a94fb8b94c
ci: SHA-pin third-party actions in workflow files (#1193)
Pin astral-sh/setup-uv and amannn/action-semantic-pull-request to
full commit SHAs to prevent supply chain attacks via tag hijacking.
2026-04-15 23:36:07 -07:00
..
workflows ci: SHA-pin third-party actions in workflow files (#1193) 2026-04-15 23:36:07 -07:00
dependabot.yml chore: add dependabot.yml with uv, docker, and github-actions coverage (#1192) 2026-04-15 23:35:42 -07:00