Skip to content

[pull] master from apify:master - #270

Merged
pull[bot] merged 1 commit into
code:masterfrom
apify:master
Aug 20, 2026
Merged

[pull] master from apify:master#270
pull[bot] merged 1 commit into
code:masterfrom
apify:master

Conversation

@pull

@pull pull Bot commented Aug 20, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

This pins every third-party action in our workflows to a full commit
SHA, keeping the resolved version tag as a trailing comment. Renovate
understands that convention and updates the SHA and comment together.

The trigger: yesterday the `v11` tag of `EndBug/add-and-commit` moved to
the broken v11.1.0 release, whose `action.yml` fails to load
(`Unrecognized named-value: 'github'`), which killed our publish
workflow ([failed
run](https://github.com/apify/crawlee/actions/runs/32255557318)). With
SHA pins, a tag moving under us, by accident or by compromise, can't
break or hijack CI anymore. `EndBug/add-and-commit` is pinned to
v11.0.0, the last working release; the upstream fix is pending in
EndBug/add-and-commit#783.

Own-org references (`apify/workflows`, `apify/actions`,
`apify/setup-apify-cli-action`) stay on floating refs on purpose, since
we control those repos.
@pull pull Bot locked and limited conversation to collaborators Aug 20, 2026
@pull pull Bot added the ⤵️ pull label Aug 20, 2026
@pull
pull Bot merged commit d57a413 into code:master Aug 20, 2026
@pull
pull Bot had a problem deploying to github-pages August 20, 2026 17:45 Failure
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant