Skip to content

Verify SHA belongs to released version #110

@assignUser

Description

@assignUser

On top of that that makes it quite hard if the pinned hash actually corresponds to an actual released version of the action which could lead to the case where somebody might getting a commit hash approved that is not actually a released version. I would certainly add version comment for each action and add a validation to see if it really corresponds to the tag.

@netomi in slack

Metadata

Metadata

Assignees

No one assigned

    Labels

    gatewayThings related to the GitHub Actions allowlist gateway

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions