Skip to content

Pin version of GitHub Actions using SHA#26

Merged
odanado merged 1 commit intomainfrom
pin-hash
Mar 19, 2025
Merged

Pin version of GitHub Actions using SHA#26
odanado merged 1 commit intomainfrom
pin-hash

Conversation

@odanado
Copy link
Member

@odanado odanado commented Mar 19, 2025

Description

To mitigate supply chain attacks in GitHub Actions, I pinned the version of GitHub Actions using SHA.
https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/

@odanado odanado requested a review from a team as a code owner March 19, 2025 01:11
@odanado odanado merged commit 188a12c into main Mar 19, 2025
1 check passed
@odanado odanado deleted the pin-hash branch March 19, 2025 09:18
@soranakahara soranakahara added the type: improvement Enhancement label Nov 11, 2025
@github-actions github-actions bot mentioned this pull request Nov 11, 2025
@soranakahara soranakahara added type: maintenance Changes related to maintenance, such as CI configuration and removed type: improvement Enhancement labels Nov 14, 2025
@github-actions github-actions bot mentioned this pull request Nov 14, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: maintenance Changes related to maintenance, such as CI configuration

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

Comments