1. 38a8b20 Remove Expired Refs by asfgit · 8 hours ago main
  2. 8d7b862 Remove Expired Refs by asfgit · 3 days ago
  3. 64ac8ea Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 4 days ago
  4. 6ebb92e action-allowlist-review: bump pypa/cibuildwheel (#938) by dependabot[bot] · 4 days ago
  5. be7412d action-allowlist-review: bump commit-check/commit-check-action (#937) by dependabot[bot] · 4 days ago
  6. ea2e0d0 action-allowlist-review: bump rubygems/release-gem (#936) by dependabot[bot] · 4 days ago
  7. 1dfe2d5 action-allowlist-review: bump rubygems/configure-rubygems-credentials (#935) by dependabot[bot] · 4 days ago
  8. 07a3fe8 action-allowlist-review: bump gradle/actions (#934) by dependabot[bot] · 4 days ago
  9. 7b1fcf8 Remove Expired Refs by asfgit · 4 days ago
  10. 71b3861 build(deps): bump urllib3 from 2.6.3 to 2.7.0 in /pelican (#933) by dependabot[bot] · 5 days ago
  11. 084b98c build(deps-dev): bump ruff from 0.15.15 to 0.15.16 in /pelican (#930) by dependabot[bot] · 5 days ago
  12. c740a61 build(deps-dev): bump ruff from 0.15.15 to 0.15.16 in /stash (#931) by dependabot[bot] · 5 days ago
  13. 943bda8 Remove Expired Refs by asfgit · 5 days ago
  14. 6e68463 Improve tests for "check GitHub actions-SHAs" (#917) by Robert Stupp · 6 days ago
  15. 00d11ed build(deps): bump github/codeql-action in /.github/workflows (#929) by dependabot[bot] · 6 days ago
  16. d4fc0a2 Verify GH action tag/SHA combinations (#356) by Robert Stupp · 6 days ago
  17. 78b8101 Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 6 days ago
  18. 04a0cda Add goreleaser/goreleaser-action to the GitHub Actions allowlist (#921) by Alex Stephen · 6 days ago
  19. 8c1bf27 build(deps): bump urllib3 from 2.6.3 to 2.7.0 (#927) by dependabot[bot] · 6 days ago
  20. 8783673 Bump urllib3 from 2.6.3 to 2.7.0 in /utils (#928) by dependabot[bot] · 6 days ago
  21. 101cb94 Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 6 days ago
  22. d20aec7 action-allowlist-review: bump pypa/cibuildwheel (#919) by dependabot[bot] · 6 days ago
  23. 7b58c60 Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 6 days ago
  24. 47590c6 action-allowlist-review: bump SonarSource/sonarqube-scan-action (#922) by dependabot[bot] · 6 days ago
  25. cbc93e2 build(deps): bump actions/checkout in /.github/workflows (#923) by dependabot[bot] · 6 days ago
  26. 5cab954 build(deps): bump github/codeql-action in /.github/workflows (#924) by dependabot[bot] · 6 days ago
  27. af94c7d build(deps): bump astral-sh/setup-uv in /.github/workflows (#926) by dependabot[bot] · 6 days ago
  28. 782c1a9 Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 6 days ago
  29. f5ac497 action-allowlist-review: bump gradle/actions (#925) by dependabot[bot] · 6 days ago
  30. 17ba1b2 Remove Expired Refs by asfgit · 7 days ago
  31. 437608c Fix current Zizmor workflow failures (#918) by Robert Stupp · 9 days ago
  32. 6c512df gateway: emit with.version for known unpinned-tools actions (#893) by Jarek Potiuk · 9 days ago
  33. 650f242 build(deps): bump zizmorcore/zizmor-action in /.github/workflows (#885) by dependabot[bot] · 12 days ago
  34. 55624bc Bump ruff from 0.15.14 to 0.15.15 in /pelican (#913) by dependabot[bot] · 12 days ago
  35. e7c26e7 Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 12 days ago
  36. a63b68b Bump ruff from 0.15.14 to 0.15.15 in /stash (#914) by dependabot[bot] · 12 days ago
  37. 2380628 Allow newer rubygems/release-gem (#907) by Erick Guan · 12 days ago
  38. 2b04b6b action-allowlist-review: bump carabiner-dev/actions (#911) by dependabot[bot] · 12 days ago
  39. df5bdc0 verify: accept validate* checksum helpers as JS download verification (#912) by Jarek Potiuk · 12 days ago
  40. 40884a2 Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 12 days ago
  41. 91fb88c Merge pull request #910 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/astral-sh/setup-uv-8.2.0 by Jarek Potiuk · 12 days ago
  42. dd5b189 action-allowlist-review: bump astral-sh/setup-uv by dependabot[bot] · 12 days ago
  43. 15cbbdc Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 12 days ago
  44. 4fbc603 Merge pull request #905 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/snok/install-poetry-1.4.2 by Jarek Potiuk · 12 days ago
  45. fdada5d Merge pull request #908 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/aws-actions/configure-aws-credentials-6.2.0 by Jarek Potiuk · 12 days ago
  46. 012ddc8 Merge pull request #909 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/graalvm/setup-graalvm-1.5.4 by Jarek Potiuk · 12 days ago
  47. 639dd7f action-allowlist-review: bump graalvm/setup-graalvm by dependabot[bot] · 13 days ago
  48. f53e0e8 action-allowlist-review: bump aws-actions/configure-aws-credentials by dependabot[bot] · 2 weeks ago
  49. e282b81 action-allowlist-review: bump snok/install-poetry by dependabot[bot] · 2 weeks ago
  50. 0ba1415 Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 3 weeks ago
  51. 05af75c Merge pull request #904 from bfabio/publiccode-parser-action by Jarek Potiuk · 3 weeks ago
  52. c58cf38 Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 3 weeks ago
  53. 0bcd1cb Merge pull request #895 from apache/allowlist-carabiner-download-and-verify-v117 by Jarek Potiuk · 3 weeks ago
  54. 51ccc23 Add italia/publiccode-parser-action to the allowlist by Fabio Bonelli · 3 weeks ago
  55. 687db60 Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 3 weeks ago
  56. 3573a76 Merge pull request #900 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/matlab-actions/run-tests-3.2 by Jarek Potiuk · 3 weeks ago
  57. eae8fa0 Merge pull request #903 from apache/dependabot/github_actions/dot-github/workflows/github/codeql-action-4.36.0 by Jarek Potiuk · 3 weeks ago
  58. 88f9010 Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 3 weeks ago
  59. b87d609 Merge pull request #902 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/aws-actions/configure-aws-credentials-6.1.3 by Jarek Potiuk · 3 weeks ago
  60. 05b0ac1 Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 3 weeks ago
  61. d6cb681 Merge pull request #901 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/sbt/setup-sbt-1.2.1 by Jarek Potiuk · 3 weeks ago
  62. cd5d644 Merge pull request #899 from apache/dependabot/uv/stash/ruff-0.15.14 by Jarek Potiuk · 3 weeks ago
  63. e1de674 Merge pull request #898 from apache/dependabot/uv/pelican/ruff-0.15.14 by Jarek Potiuk · 3 weeks ago
  64. 129c148 Merge pull request #897 from apache/dependabot/uv/pelican/types-markdown-3.10.2.20260518 by Jarek Potiuk · 3 weeks ago
  65. 2221f29 Merge pull request #896 from apache/dependabot/uv/pelican/types-requests-2.33.0.20260518 by Jarek Potiuk · 3 weeks ago
  66. 301bd08 build(deps): bump github/codeql-action in /.github/workflows by dependabot[bot] · 3 weeks ago
  67. 4198ad2 action-allowlist-review: bump aws-actions/configure-aws-credentials by dependabot[bot] · 3 weeks ago
  68. 4a98174 action-allowlist-review: bump sbt/setup-sbt by dependabot[bot] · 3 weeks ago
  69. c843d8e action-allowlist-review: bump matlab-actions/run-tests by dependabot[bot] · 3 weeks ago
  70. f6fb10e build(deps-dev): bump ruff from 0.15.13 to 0.15.14 in /stash by dependabot[bot] · 3 weeks ago
  71. da85059 build(deps-dev): bump ruff from 0.15.13 to 0.15.14 in /pelican by dependabot[bot] · 3 weeks ago
  72. 1c77c17 build(deps-dev): bump types-markdown in /pelican by dependabot[bot] · 3 weeks ago
  73. f4602c3 build(deps-dev): bump types-requests in /pelican by dependabot[bot] · 3 weeks ago
  74. f88b862 allowlist: add carabiner-dev install/download-and-verify v1.1.7 transitive by Jarek Potiuk · 3 weeks ago
  75. d65640e Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 3 weeks ago
  76. c6ff2c5 Merge pull request #894 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/scalacenter/sbt-dependency-submission-3.2.3 by Jarek Potiuk · 3 weeks ago
  77. 3c335f8 Sync actions.yml, composite action, and approved_patterns.yml by asfgit · 3 weeks ago
  78. d985d79 action-allowlist-review: bump scalacenter/sbt-dependency-submission by dependabot[bot] · 3 weeks ago
  79. e77dd14 hotfix: restore ALLOWLIST_WORKFLOW_TOKEN PAT in update.yml (#892) by Jarek Potiuk · 3 weeks ago
  80. b7b9ced Remove Expired Refs by asfgit · 3 weeks ago
  81. 2a9abd3 Merge pull request #886 from apache/zizmor-ignore-1password-unpinned-tools by Jarek Potiuk · 3 weeks ago
  82. ecb086f Merge pull request #846 from kevingurney/matlab-actions-run-tests-3-1-1 by Jarek Potiuk · 3 weeks ago
  83. cb79995 Add support for v3.1.2 of matlab-actions/run-tests. by Kevin Gurney · 5 weeks ago
  84. eb27420 Merge pull request #889 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/aws-actions/configure-aws-credentials-6.1.2 by Jarek Potiuk · 3 weeks ago
  85. 137df70 workflows: fix allowlist race, inline cap check, drop PAT (#866) (#876) by Jarek Potiuk · 3 weeks ago
  86. d02ee25 Update actions.yml and approved_patterns.yml based on .github/actions/for-dependabot-triggered-reviews/action.yml by asfgit · 3 weeks ago
  87. 6a3478f Merge pull request #890 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/docker/setup-qemu-action-4.1.0 by Jarek Potiuk · 3 weeks ago
  88. 06f95e3 Update actions.yml and approved_patterns.yml based on .github/actions/for-dependabot-triggered-reviews/action.yml by asfgit · 3 weeks ago
  89. 35d949b action-allowlist-review: bump sbt/setup-sbt (#888) by dependabot[bot] · 3 weeks ago
  90. e49da45 action-allowlist-review: bump docker/setup-qemu-action by dependabot[bot] · 3 weeks ago
  91. 33e0424 action-allowlist-review: bump aws-actions/configure-aws-credentials by dependabot[bot] · 3 weeks ago
  92. 7626bc2 Remove Expired Refs by asfgit · 3 weeks ago
  93. d7dc387 allowlist: silence zizmor unpinned-tools on if:false 1Password load-secrets-action by Jarek Potiuk · 3 weeks ago
  94. ce591c9 Update actions.yml and approved_patterns.yml based on .github/actions/for-dependabot-triggered-reviews/action.yml by asfgit · 3 weeks ago
  95. e1bfa7e Merge pull request #884 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/docker/setup-buildx-action-4.1.0 by Jarek Potiuk · 3 weeks ago
  96. 0f1c2fc Update actions.yml and approved_patterns.yml based on .github/actions/for-dependabot-triggered-reviews/action.yml by asfgit · 3 weeks ago
  97. 4c3ac48 Merge pull request #865 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/manusa/actions-setup-minikube-2.18.0 by Jarek Potiuk · 3 weeks ago
  98. 742f57c Update actions.yml and approved_patterns.yml based on .github/actions/for-dependabot-triggered-reviews/action.yml by asfgit · 3 weeks ago
  99. 05b22ab Merge pull request #855 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/opentofu/setup-opentofu-2.0.1 by Jarek Potiuk · 3 weeks ago
  100. f0a8225 Merge pull request #878 from apache/dependabot/github_actions/dot-github/actions/for-dependabot-triggered-reviews/golangci/golangci-lint-action-9.2.1 by Jarek Potiuk · 3 weeks ago