Skip to content

Conversation

@thpierce
Copy link
Contributor

Add validation step to require commit SHAs instead of version tags for third-party GitHub actions in workflow files. Repo config Require actions to be pinned to a full-length commit SHA will protect against this if we missed any others.

Testing done

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@thpierce thpierce requested a review from a team as a code owner September 22, 2025 21:14
@thpierce thpierce added the skip changelog doesn't need a CHANGELOG entry label Sep 22, 2025
@thpierce thpierce merged commit 9b6fcc9 into main Sep 23, 2025
7 checks passed
@thpierce thpierce deleted the no-version branch September 23, 2025 23:32
jj22ee pushed a commit that referenced this pull request Oct 24, 2025
Add validation step to require commit SHAs instead of version tags for
third-party GitHub actions in workflow files. Repo config `Require
actions to be pinned to a full-length commit SHA` will protect against
this if we missed any others.

### Testing done
* See:
aws-observability/aws-otel-python-instrumentation#475

By submitting this pull request, I confirm that my contribution is made
under the terms of the Apache 2.0 license.
jj22ee pushed a commit that referenced this pull request Oct 24, 2025
Add validation step to require commit SHAs instead of version tags for
third-party GitHub actions in workflow files. Repo config `Require
actions to be pinned to a full-length commit SHA` will protect against
this if we missed any others.

### Testing done
* See:
aws-observability/aws-otel-python-instrumentation#475

By submitting this pull request, I confirm that my contribution is made
under the terms of the Apache 2.0 license.
jj22ee pushed a commit that referenced this pull request Oct 27, 2025
Add validation step to require commit SHAs instead of version tags for
third-party GitHub actions in workflow files. Repo config `Require
actions to be pinned to a full-length commit SHA` will protect against
this if we missed any others.

### Testing done
* See:
aws-observability/aws-otel-python-instrumentation#475

By submitting this pull request, I confirm that my contribution is made
under the terms of the Apache 2.0 license.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip changelog doesn't need a CHANGELOG entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants