Skip to content

Pin GH Actions to commit sha#1494

Open
thomasferrandiz wants to merge 1 commit intomasterfrom
pin-actions-to-sha
Open

Pin GH Actions to commit sha#1494
thomasferrandiz wants to merge 1 commit intomasterfrom
pin-actions-to-sha

Conversation

@thomasferrandiz
Copy link
Collaborator

@thomasferrandiz thomasferrandiz commented Mar 25, 2026

Pin GH Actions to commit sha
This help mitigates supply-chain attack like this one: https://www.stepsecurity.io/blog/trivy-compromised-a-second-time---malicious-v0-69-4-release

@gemini-code-assist
Copy link

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

@coveralls
Copy link

Coverage Status

coverage: 50.499% (-0.2%) from 50.679%
when pulling 6a6fb45 on pin-actions-to-sha
into 132c5e7 on master.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants