Following the discussion in https://github.com/apache/infrastructure-actions/pull/674#issuecomment-4216174449 Possible criteria: - [x] Reproducibility - [x] Code review of differences vs. past approved version - [x] Passing cooldown (4 days now) - [ ] Correctness of the action (for example errors in build pipelines) - [ ] Hash-pinning of composite actions - [ ] Compatible licencing Maybe others? I would love to hear what others think.
Following the discussion in #674 (comment)
Possible criteria:
Maybe others?
I would love to hear what others think.