From e207c35e7ce5bc6fdf30be9e0464a66100c000f9 Mon Sep 17 00:00:00 2001 From: Simon de Haan Date: Tue, 12 May 2026 14:58:52 +0200 Subject: [PATCH] Pin CLA assistant action to commit SHA The CLA workflow uses pull_request_target which runs from the base branch, so this fix must be on develop to take effect. Co-Authored-By: Claude Opus 4.6 (1M context) --- .github/workflows/cla.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/cla.yml b/.github/workflows/cla.yml index 53cb43c8..ae351153 100644 --- a/.github/workflows/cla.yml +++ b/.github/workflows/cla.yml @@ -19,7 +19,7 @@ jobs: - name: "CLA Assistant" if: (github.event.comment.body == 'recheck' || github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA') || github.event_name == 'pull_request_target' # Beta Release - uses: contributor-assistant/github-action@v2.6.1 + uses: contributor-assistant/github-action@ca4a40a7d1004f18d9960b404b97e5f30a505a08 # v2.6.1 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # the below token should have repo scope and must be manually added by you in the repository's secret