fix(ci): pin actions to their commit sha

Floating tags let a compromised or force pushed release change what the workflows execute. Pinning the actions to a
commit sha and restricting the default token to read access limits the blast radius of a supply chain attack. The
outdated ansible-lint and markdownlint-cli2 versions are raised along with the pinning.

The ansible-lint run installs the collections of the molecule scenario, because the scenario is linted as well and
depends on community.docker beside the community.general requirement of the role.

Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
2026-09-10 21:41:34 +02:00
co-authored by Copilot
parent e2f248e28d
commit ee977a8610
3 changed files with 11 additions and 0 deletions
+3
View File
@@ -7,6 +7,9 @@ on:
branches: [ '**' ]
tags-ignore: [ '**' ]
permissions:
contents: read
jobs:
markdown-lint:
runs-on: