Comment on GitHub Actions is the weakest linkparentComments−pabs34moBetter to treat it as a dependency still, but audit each new commit/release as it comes in, and pin to the exact last commit id that you verified.−deepsun4moYes, but no one audits new dependencies versions usually. Only Release Notes mostly.
Comments
Better to treat it as a dependency still, but audit each new commit/release as it comes in, and pin to the exact last commit id that you verified.
Yes, but no one audits new dependencies versions usually. Only Release Notes mostly.