Skip to content

Pin build-logic workflow refs to commit SHA#288

Closed
jandroav wants to merge 1 commit into
ddbfrom
DAT-22394-pin-build-logic-sha
Closed

Pin build-logic workflow refs to commit SHA#288
jandroav wants to merge 1 commit into
ddbfrom
DAT-22394-pin-build-logic-sha

Conversation

@jandroav
Copy link
Copy Markdown

@jandroav jandroav commented Mar 6, 2026

Summary

  • Pin liquibase/build-logic reusable workflow refs from @main to a commit SHA
  • Prevents supply chain attacks if build-logic/main branch is compromised

Test plan

  • Verify workflows still trigger correctly (the SHA points to the same commit as main)

DAT-22394

Replace @main with @3bc448f805496d87c284977b62cda22c5aad540d for supply chain protection.

DAT-22394

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@jandroav jandroav closed this Mar 6, 2026
@jandroav jandroav deleted the DAT-22394-pin-build-logic-sha branch March 6, 2026 04:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant