Skip to content

Bump spring-io/spring-release-actions from 0.0.3 to 0.0.4

6731aa2
Select commit
Loading
Failed to load commit list.
Merged

Bump spring-io/spring-release-actions from 0.0.3 to 0.0.4 #19095

Bump spring-io/spring-release-actions from 0.0.3 to 0.0.4
6731aa2
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Apr 17, 2026 in 5s

4 new alerts including 4 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 4 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 21 in .github/workflows/defer-issues.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Defer Issues' step
Uses Step: compute-version
uses 'spring-io/spring-release-actions/compute-version' with ref '0.0.4', not a pinned commit hash

Check warning on line 24 in .github/workflows/defer-issues.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Defer Issues' step
Uses Step: todays-release
uses 'spring-io/spring-release-actions/get-todays-release-version' with ref '0.0.4', not a pinned commit hash

Check warning on line 31 in .github/workflows/defer-issues.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Defer Issues' step
Uses Step: next-version
uses 'spring-io/spring-release-actions/compute-next-version' with ref '0.0.4', not a pinned commit hash

Check warning on line 35 in .github/workflows/defer-issues.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Defer Issues' step
Uses Step
uses 'spring-io/spring-release-actions/schedule-milestone' with ref '0.0.4', not a pinned commit hash