Skip to content

Conversation

thpierce
Copy link
Contributor

Add validation step to require commit SHAs instead of version tags for third-party GitHub actions in workflow files. Repo config Require actions to be pinned to a full-length commit SHA will protect against this if we missed any others.

Testing done

Rollback procedure:

Git revert - no risk

Ensure you've run the following tests on your changes and include the link below:

pr workflow sufficient

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@thpierce thpierce changed the title Scan for @v actions feat: prevent versioned 3P GitHub actions in PR builds Sep 22, 2025
@thpierce thpierce merged commit a7bc14c into main Sep 23, 2025
10 checks passed
@thpierce thpierce deleted the no-version branch September 23, 2025 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants