Skip to content

chore: [SEC-7924] pin third-party GitHub Actions to commit SHAs#452

Merged
Vadman97 merged 1 commit intomainfrom
security/SEC-7924/pin-github-actions
Apr 1, 2026
Merged

chore: [SEC-7924] pin third-party GitHub Actions to commit SHAs#452
Vadman97 merged 1 commit intomainfrom
security/SEC-7924/pin-github-actions

Conversation

@pkaeding
Copy link
Copy Markdown
Contributor

@pkaeding pkaeding commented Mar 31, 2026

Summary

Pin all third-party GitHub Actions to full-length commit SHAs to prevent supply chain attacks.

Addresses findings from the third-party-action-not-pinned-to-commit-sha Semgrep rule.

Test plan

  • Verify CI passes with pinned action SHAs

Related Jira issue: SEC-7924: Unpinned GitHub Actions remediation

Pin all third-party GitHub Actions to full-length commit SHAs to prevent
supply chain attacks. Addresses findings from the
third-party-action-not-pinned-to-commit-sha Semgrep rule.
@pkaeding pkaeding requested a review from a team as a code owner March 31, 2026 22:48
@launchdarkly-upra launchdarkly-upra bot changed the title chore: pin third-party GitHub Actions to commit SHAs chore: [SEC-7924] pin third-party GitHub Actions to commit SHAs Mar 31, 2026
@Vadman97 Vadman97 enabled auto-merge (squash) April 1, 2026 14:56
@Vadman97 Vadman97 merged commit 853944a into main Apr 1, 2026
25 of 28 checks passed
@Vadman97 Vadman97 deleted the security/SEC-7924/pin-github-actions branch April 1, 2026 15:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants