Skip to content

Pin 3rd-party actions to SHA1#93

Open
fbricon wants to merge 1 commit into
redhat-developer:masterfrom
fbricon:pin-actions-sha1
Open

Pin 3rd-party actions to SHA1#93
fbricon wants to merge 1 commit into
redhat-developer:masterfrom
fbricon:pin-actions-sha1

Conversation

@fbricon
Copy link
Copy Markdown

@fbricon fbricon commented Feb 17, 2023

Hi!

Following the GH Action Security Hardening guide we should use the commit SHA instead of the branch or tag for any third-party untrusted action.

This PR was submitted by a script.

@xsuchy
Copy link
Copy Markdown
Collaborator

xsuchy commented Feb 17, 2023

@pmkovar can you review it, please? And can use update the secrets in CI?

@pmkovar
Copy link
Copy Markdown
Collaborator

pmkovar commented Feb 20, 2023

@fbricon This change seems to trigger an error with an empty secret, would you know why?

I've double checked the secrets are set up correctly, see the latest build on master: https://github.com/redhat-developer/rpm-packaging-guide/actions/runs/4115283392/jobs/7335909142.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants