Skip to content

Pin GitHub Actions to commit hashes#3020

Open
pocke wants to merge 1 commit into
ruby:masterfrom
pocke:Pin_GitHub_Actions_to_commit_hashes
Open

Pin GitHub Actions to commit hashes#3020
pocke wants to merge 1 commit into
ruby:masterfrom
pocke:Pin_GitHub_Actions_to_commit_hashes

Conversation

@pocke

@pocke pocke commented Jun 29, 2026

Copy link
Copy Markdown
Member

Run pinact to replace mutable tag references (e.g. actions/checkout@v7) with their corresponding full commit SHAs, keeping the version tag as a trailing comment. Pinning to immutable SHAs prevents a compromised or retagged action from silently changing behavior in CI.

Generated with: pinact run (pinact v4.1.0)

Run pinact to replace mutable tag references (e.g. actions/checkout@v7)
with their corresponding full commit SHAs, keeping the version tag as a
trailing comment. Pinning to immutable SHAs prevents a compromised or
retagged action from silently changing behavior in CI.

Generated with: pinact run (pinact v4.1.0)

ハッシュ固め夜半の月さえ動かさず
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants