This PR hash-pins all Actions used in workflows and sets up dependabot
to keep them up-to-date.
Dependabot will send at most one PR per month. That PR will update the
hashes and version comments of all Actions with new versions.
I also suggest you enable Dependabot Security Updates in the repo's
[Code security &
settings (if you haven't already). This will make Dependabot send a PR
as soon as a dependency is found to have a vulnerability.
Signed-off-by: Pedro Kaj Kjellerup Nacht <pnacht@google.com>