fix(ci): pin actions to their commit sha

Floating tags let a compromised or force pushed release change what the workflows execute. Pinning the actions to a
commit sha and restricting the default token to read access limits the blast radius of a supply chain attack. The
outdated ansible-lint and markdownlint-cli2 versions are raised along with the pinning.

The ansible-lint run installs the collections of the molecule scenario, because the scenario is linted as well and
depends on community.docker beside the community.general requirement of the role.

Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
2026-09-10 21:41:34 +02:00
co-authored by Copilot
parent e2f248e28d
commit ee977a8610
3 changed files with 11 additions and 0 deletions
+5
View File
@@ -7,6 +7,9 @@ on:
branches: [ '**' ]
tags-ignore: [ '**' ]
permissions:
contents: read
jobs:
ansible-lint:
runs-on:
@@ -17,4 +20,6 @@ jobs:
uses: ansible/ansible-lint@665d9e07a1943254d2910faffc106adaf7ea7294 # v26.8.0
with:
args: "--config-file .ansible-lint"
# The molecule scenario is linted as well, so its collections are required beside the ones of the role.
requirements_file: "molecule/default/collections.yml"
setup_python: "true"