-
Notifications
You must be signed in to change notification settings - Fork 641
[github actions] Pin actions to hash commits #6784
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Tags can be modified to point to different commits, which is a security issue. By pinning to specific commits we ensure the code executing isn't changing.
📝 PRs merging into main branchOur main branch should always be in a releasable state. If you are working on a larger change, or if you don't want this change to see the light of the day just yet, consider using a feature branch first, and only merge into the main branch when the code complete and ready to be released. |
@dconeybe please check the changes to the dataconnect actions |
Test Results 1 062 files + 45 1 062 suites +45 34m 57s ⏱️ +51s For more details on these failures, see this check. Results for commit 17555ed. ± Comparison against base commit af1fe93. ♻️ This comment has been updated with latest results. |
Size Report 1Affected ProductsNo changes between base commit (af1fe93) and merge commit (1597d7a).Test Logs |
dataconnect changes LGTM. I'm not going to mark this PR as "approved" since my review is only on a small subset of the file; rather, I'll remove myself from the list of reviewers. |
Coverage Report 1Affected Products
Test Logs |
Tags can be modified to point to different commits, which is a security issue. By pinning to specific commits we ensure the code executing isn't changing.
Tags can be modified to point to different commits, which is a
security issue. By pinning to specific commits we ensure the code
executing isn't changing.