ci: vendor validation scripts and remove remote action pins - #136
Conversation
CI failed: CI failures caused by Gitleaks and Hypatia compliance scans detecting secrets and missing configuration/headers in the repository, alongside intermittent Erlang TLS certificate handshake errors downloading Rebar from builds.hex.pm.OverviewAnalysis of 5 CI logs revealed two primary categories of failures: change-related security/compliance gate failures (Gitleaks secret detection and Hypatia audit scanner finding unmasked secrets, missing SPDX headers, and workflow timeout issues), and infrastructure/dependency failures due to Erlang TLS handshake alerts ( FailuresGitleaks & Hypatia Compliance Gate Failures (confidence: high)
Erlang/Mix TLS Handshake Failure (confidence: high)
Summary
Code Review ✅ ApprovedVendors validation scripts and removes remote action pins to fix CI workflows after deleted actions. No issues found.
Tip Comment OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
Automated PR to fix CI after deleted actions.