mirror of
https://github.com/feder-cr/invisible_playwright.git
synced 2026-06-13 08:55:12 +02:00
ci: pin actions to SHA + single-source the playwright pin (audit B6/B4)
B6: pin every third-party action in the build/publish path to an immutable commit SHA (a retagged actions/checkout or action-gh-release would otherwise inject code into the binary users download). The other workflows (tests, webrtc, launch-matrix) handle no secrets, so they're left on tags. B4: the playwright pin lived in two workflow files with no shared source. Move it to scripts/playwright_pin.txt that both read, so they can't drift. The drive gate already ENFORCES playwright<->juggler compatibility (an incompatible pin fails the launch/drive and nothing publishes); the file is the single bump point when the juggler is re-synced.
This commit is contained in:
parent
5dac302938
commit
62cdf626a0
3 changed files with 21 additions and 12 deletions
1
scripts/playwright_pin.txt
Normal file
1
scripts/playwright_pin.txt
Normal file
|
|
@ -0,0 +1 @@
|
|||
1.55.0
|
||||
Loading…
Add table
Add a link
Reference in a new issue