Skip to content

Pin dependencies using SHA hashes instead of tags#326

Merged
antas-marcin merged 1 commit into
mainfrom
actions-version-change-from--gha-to-sha
Apr 10, 2026
Merged

Pin dependencies using SHA hashes instead of tags#326
antas-marcin merged 1 commit into
mainfrom
actions-version-change-from--gha-to-sha

Conversation

@antas-marcin
Copy link
Copy Markdown
Collaborator

@antas-marcin antas-marcin commented Apr 10, 2026

Pin GitHub Actions dependencies to commit SHAs instead of mutable version tags for supply chain security.

Action SHA Version
actions/checkout 34e11487... v4
actions/checkout f43a0e5f... v3 (2 occurrences)
aquasecurity/trivy-action 57a97c7e... 0.35.0
softprops/action-gh-release 26994186... v1
actions/setup-python 7f4fc3e2... v4
azure/setup-helm 5119fcb9... v3

@antas-marcin antas-marcin requested a review from a team as a code owner April 10, 2026 07:29
Copy link
Copy Markdown

@orca-security-eu orca-security-eu Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Orca Security Scan Summary

Status Check Issues by priority
Passed Passed Secrets high 0   medium 0   low 0   info 0 View in Orca

@antas-marcin antas-marcin merged commit d7b92d0 into main Apr 10, 2026
3 of 4 checks passed
@antas-marcin antas-marcin deleted the actions-version-change-from--gha-to-sha branch April 10, 2026 16:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants