HTTP/1.1 200 OK Date: Thu, 08 Jan 2026 08:29:50 GMT Content-Type: text/html; charset=utf-8 Cache-Control: no-cache Content-Security-Policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com/ copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/ Referrer-Policy: no-referrer-when-downgrade server-timing: pull_request_layout-fragment;desc="pull_request_layout fragment";dur=442.94049,conversation_content-fragment;desc="conversation_content fragment";dur=2944.423134,conversation_sidebar-fragment;desc="conversation_sidebar fragment";dur=346.554155,nginx;desc="NGINX";dur=1.391976,glb;desc="GLB";dur=52.293859 Strict-Transport-Security: max-age=31536000; includeSubdomains; preload Vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With X-Content-Type-Options: nosniff X-Frame-Options: deny x-voltron-version: 69ef6d1 X-XSS-Protection: 0 Server: github.com Content-Encoding: gzip Accept-Ranges: bytes Set-Cookie: _gh_sess=6eE3l4JuPG9uWM57IbbICKLTm1gaa%2Fi0x8RKiLvf8MDnhR95Rmwk%2FShSjmQ6EWg6055uCYRgVgDq%2F%2FCyTUDduCSV%2B37rEPL4%2B2Al8BymWGWP8kKM6I6YkWcF9BAVH4gFKJAl4dspbnCrMrrTj3BduC2DErn%2FA98uOqIOTPGFNgF6WRilALHrB6it%2BZQLHtpTxJfrQHEAEQgV1Ys4MLqE5eIV80Q9lmBQCiH1F6wQ8LqKMxgo4ZcWO63mS27GVGorKDUSQYAW%2Flm6e4RyO0F9%2FA%3D%3D--PeB6LYfNfAWnasTr--e6NPx006WIwH4gqYs40x4w%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax Set-Cookie: _octo=GH1.1.2088177666.1767860987; Path=/; Domain=github.com; Expires=Fri, 08 Jan 2027 08:29:47 GMT; Secure; SameSite=Lax Set-Cookie: logged_in=no; Path=/; Domain=github.com; Expires=Fri, 08 Jan 2027 08:29:47 GMT; HttpOnly; Secure; SameSite=Lax X-GitHub-Request-Id: AA5E:18F4D8:8A36C8C:7493E0B:695F6AFA Transfer-Encoding: chunked Improvements to the worst package manager by Boosted-Bonobo · Pull Request #2346 · actions/checkout · GitHub
🌐 شما از Web Proxy استفاده می‌کنید صفحه اصلی
Skip to content

Conversation

@Boosted-Bonobo
Copy link

I was surprised to see that this article is right.
This pull request aims to improve the ecosystem as this is quite a commonly used github action.
I'd also like to refer you to immutable releases which should be done from now on.

@Boosted-Bonobo
Copy link
Author

Boosted-Bonobo commented Dec 15, 2025

Since this is going to take a while to do and not just do, but also the time it will take to update to use a newer version which has the uses pinned, I'll create and update the below list of the PRs to check the overall progress:

#2346
actions/setup-node#1451
actions/publish-action#121
actions/reusable-workflows#27
pnpm/action-setup#199
actions/upload-artifact#746
actions/download-artifact#453

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant