Skip to content

chore: pin GitHub Actions to SHA hashes#75

Open
yylian wants to merge 1 commit intodefaultfrom
update/actions-to-sha
Open

chore: pin GitHub Actions to SHA hashes#75
yylian wants to merge 1 commit intodefaultfrom
update/actions-to-sha

Conversation

@yylian
Copy link
Copy Markdown

@yylian yylian commented Mar 26, 2026

Summary

  • Pin all GitHub Actions references to specific SHA commits instead of mutable version tags
  • Prevents supply chain attacks where a tag could be moved to point to malicious code

Test plan

  • Verify CI workflows still run correctly after the pin

Pin all GitHub Actions to specific SHA commits for improved security,
preventing supply chain attacks via mutable version tags.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant