Is there an existing issue already for this bug?
I have read the troubleshooting guide
I am running a supported version of CloudNativePG
Contact Details
No response
Version
1.26.0-rc3
What version of Kubernetes are you using?
1.32
What is your Kubernetes environment?
Self-managed: kind (evaluation)
How did you install the operator?
YAML manifest
What happened?
We have a couple of pinned dependencies missed that we should fix, probably using renovate:
Warn: third-party GitHubAction not pinned by hash: .github/workflows/continuous-delivery.yml:633: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudnative-pg/cloudnative-pg/continuous-delivery.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/continuous-integration.yml:605: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudnative-pg/cloudnative-pg/continuous-integration.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/require-labels.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudnative-pg/cloudnative-pg/require-labels.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:5
Warn: containerImage not pinned by hash: Dockerfile:10
Warn: goCommand not pinned by hash: hack/e2e/run-e2e-local.sh:70
Warn: goCommand not pinned by hash: hack/e2e/run-e2e.sh:74
Warn: pipCommand not pinned by hash: .github/workflows/continuous-delivery.yml:1533
Warn: downloadThenRun not pinned by hash: .github/workflows/continuous-integration.yml:855
Warn: pipCommand not pinned by hash: .github/workflows/latest-postgres-version-check.yml:31
Info: 92 out of 92 GitHub-owned GitHubAction dependencies pinned
Info: 110 out of 113 third-party GitHubAction dependencies pinned
Info: 0 out of 2 containerImage dependencies pinned
Info: 0 out of 2 goCommand dependencies pinned
Info: 0 out of 2 pipCommand dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned
Cluster resource
Relevant log output
Code of Conduct
Is there an existing issue already for this bug?
I have read the troubleshooting guide
I am running a supported version of CloudNativePG
Contact Details
No response
Version
1.26.0-rc3
What version of Kubernetes are you using?
1.32
What is your Kubernetes environment?
Self-managed: kind (evaluation)
How did you install the operator?
YAML manifest
What happened?
We have a couple of pinned dependencies missed that we should fix, probably using renovate:
Cluster resource
Relevant log output
Code of Conduct