Skip to content

[SECENG-364] Pin GitHub Actions to commit SHAs#86

Merged
Stephanie Ginovker (sginovker) merged 1 commit intomainfrom
security/pin-actions-to-sha
Apr 8, 2026
Merged

[SECENG-364] Pin GitHub Actions to commit SHAs#86
Stephanie Ginovker (sginovker) merged 1 commit intomainfrom
security/pin-actions-to-sha

Conversation

@sginovker
Copy link
Copy Markdown
Contributor

@sginovker Stephanie Ginovker (sginovker) commented Apr 8, 2026

Ticket

SECENG-364

Summary

Pin all external GitHub Actions to commit SHAs for supply chain security. Internal (hoverinc/) actions are left unpinned.

Pinned Actions

Dependabot

Added/updated dependabot.yml to keep GitHub Actions pinned to the latest SHA with a 7-day update cooldown.

@sginovker Stephanie Ginovker (sginovker) marked this pull request as ready for review April 8, 2026 22:41
@sginovker Stephanie Ginovker (sginovker) merged commit 461a483 into main Apr 8, 2026
3 checks passed
@sginovker Stephanie Ginovker (sginovker) deleted the security/pin-actions-to-sha branch April 8, 2026 22:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants