-
Notifications
You must be signed in to change notification settings - Fork 50
Open
Description
It's awesome that secure repo pins dependencies like GHA. However, it is ideal to keep that hygiene to ensure new dependencies that are introduced must be pinned (bonus points if it can suggest hashes). It would be great to add an action like https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions as part of secure repo or harden runner.
If this issue is more suitable for harden-repo repo, please feel free to move it there.
Metadata
Metadata
Assignees
Labels
No labels