Pin the third-party actions referenced by mutable @master/@main tags to their
current commit SHA (tag kept in a trailing comment). Several run in jobs holding
secrets:
- SonarSource/sonarcloud-github-action@master (sonarcloud-scan.yml) — SONAR_TOKEN
- Yikun/hub-mirror-action@master (sync2gitee.yml) — GITEE_PRIVATE_KEY, GITEE_TOKEN
- fit2cloud/LLM-CodeReview-Action@main (llm-code-review.yml) — tokens + LLM API key
- crate-ci/typos@master (tyops-check.yml)
A moved tag would run unreviewed code with those secrets. Behaviour unchanged;
per GitHub's guidance to pin actions to a full-length commit SHA.
Signed-off-by: Kobi Hikri <kobi.hikri@gmail.com>