Skip to content

ci: pin GitHub Actions to commit SHAs (2) - #1246

Open
mirkosalvato1-ctrl wants to merge 4 commits into
flagos-ai:mainfrom
mirkosalvato1-ctrl:pinguard/pin-actions-74493
Open

ci: pin GitHub Actions to commit SHAs (2)#1246
mirkosalvato1-ctrl wants to merge 4 commits into
flagos-ai:mainfrom
mirkosalvato1-ctrl:pinguard/pin-actions-74493

Conversation

@mirkosalvato1-ctrl

Copy link
Copy Markdown

Why

Mutable Action tags (@v4, @main) can be retagged, which is a supply-chain risk.
This PR pins third-party Actions to full commit SHAs while keeping the tag in a comment.
Official actions/* tags are left unchanged (common maintainer preference).

Pins

  • docker/setup-buildx-action@v3 -> 8d2750c68a42
  • docker/build-push-action@v6 -> 10e90e3645ea

Reference: GitHub docs on using third-party actions securely.

tengqm and others added 4 commits July 18, 2026 19:16
…#1240)

Add standard Apache 2.0 copyright header (Copyright 2026 FlagOS
Contributors) to all source files.

- **703 files** stamped with Apache 2.0 headers
- **80 files** with upstream copyright (HuggingFace, Physical
Intelligence, NVIDIA) — left untouched
- **104 files** with other licenses (51 MPL, 41 proprietary, 10 MIT, 2
BSD) — third-party/upstream code
- **31 files** skipped by rule — binary, JSON, etc.

This PR was written in part with the assistance of generative AI.
…. 2026/7/21 (flagos-ai#1244)

<!--
 Copyright 2026 FlagOS Contributors

 Licensed under the Apache License, Version 2.0 (the "License");
 you may not use this file except in compliance with the License.
 You may obtain a copy of the License at

     http://www.apache.org/licenses/LICENSE-2.0

 Unless required by applicable law or agreed to in writing, software
 distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 See the License for the specific language governing permissions and
 limitations under the License.
 -->

### PR Category
<!-- One of [ Train | Inference | Compress | Serve | RL | Core |
Hardware | CICD | Tools | Others ] -->
[CICD]
### PR Types
<!-- One of [ User Experience | New Features | Bug Fixes | Improvements
| Performance | Breaking Change| Deprecations | Test Case | Docs |
Others ] -->
Test Case
### PR Description
<!-- Describe what you’ve done -->
update  golden value of functional_test hetero_train and train.
### PR Category
<!-- One of [ Train | Inference | Compress | Serve | RL | Core |
Hardware | CICD | Tools | Others ] -->
Train
### PR Types
<!-- One of [ User Experience | New Features | Bug Fixes | Improvements
| Performance | Breaking Change| Deprecations | Test Case | Docs |
Others ] -->
Others
### PR Description
<!-- Describe what you’ve done -->
Update qwen3vl for the current `Megatron-LM-FL` and add functional
tests.
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants