Skip to content

SEC-090: Automated trusted workflow pinning (2025-03-24)#1038

Merged
tvoran merged 1 commit intomainfrom
tsccr-auto-pinning/trusted/2025-03-24
Mar 25, 2025
Merged

SEC-090: Automated trusted workflow pinning (2025-03-24)#1038
tvoran merged 1 commit intomainfrom
tsccr-auto-pinning/trusted/2025-03-24

Conversation

@hashicorp-tsccr
Copy link
Contributor

Bumping GitHub Actions version to latest TSCCR release.

  • changes in .github/actions/integration-test/action.yml
    • bump actions/download-artifact from v4.1.8 to v4.1.9 (release notes)
    • bump actions/upload-artifact from v4.6.0 to v4.6.1 (release notes)
    • bump actions/upload-artifact from v4.6.0 to v4.6.1 (release notes)
  • changes in .github/workflows/build.yaml
    • bump actions/setup-node from v4.2.0 to v4.3.0 (release notes)
    • bump actions/upload-artifact from v4.6.0 to v4.6.1 (release notes)
    • bump actions/upload-artifact from v4.6.0 to v4.6.1 (release notes)
    • bump actions/download-artifact from v4.1.8 to v4.1.9 (release notes)
    • bump azure/setup-helm from v4.2.0 to v4.3.0 (release notes)
    • bump actions/download-artifact from v4.1.8 to v4.1.9 (release notes)
    • bump azure/setup-helm from v4.2.0 to v4.3.0 (release notes)

This PR was auto-generated by security-tsccr/actions/runs/14028414411

You can alter the configuration of this automation via the hcl config in security-tsccr/automation

This PR can be regenerated by dispatching the GitHub workflow Pin Action Refs. Please reach out to #team-prodsec if you have any questions.

@hashicorp-tsccr hashicorp-tsccr bot requested a review from a team as a code owner March 24, 2025 06:09
@hashicorp-tsccr hashicorp-tsccr bot added the SEC-090/Pinning/Trusted Automated TSCCR pinning PR to trusted SHAs. label Mar 24, 2025
@tvoran tvoran merged commit 0ce8199 into main Mar 25, 2025
100 checks passed
@tvoran tvoran deleted the tsccr-auto-pinning/trusted/2025-03-24 branch March 25, 2025 00:46
@benashz benashz added this to the v1.0.0 milestone Sep 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

SEC-090/Pinning/Trusted Automated TSCCR pinning PR to trusted SHAs.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants