fix(ci): pin actions to their commit sha

Floating tags let a compromised or force pushed release change what the workflows execute. Pinning the actions to a
commit sha and restricting the default token to read access limits the blast radius of a supply chain attack. The
outdated ansible-lint and markdownlint-cli2 versions are raised along with the pinning.

The ansible-lint run installs the collections of the molecule scenario, because the scenario is linted as well and
depends on community.docker beside the community.general requirement of the role.

Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
2026-09-10 21:41:34 +02:00
co-authored by Copilot
parent e2f248e28d
commit ee977a8610
3 changed files with 11 additions and 0 deletions
+3
View File
@@ -6,6 +6,9 @@ on:
- '**'
workflow_dispatch: {}
permissions:
contents: read
jobs:
release:
name: Release Ansible Role