Skip to content

chore: pin GitHub Actions to SHA hashes#76

Open
simonlet wants to merge 3 commits intosovity/0.11.1from
chore/pin-github-actions-sha-0-11-1
Open

chore: pin GitHub Actions to SHA hashes#76
simonlet wants to merge 3 commits intosovity/0.11.1from
chore/pin-github-actions-sha-0-11-1

Conversation

@simonlet
Copy link
Copy Markdown
Collaborator

@simonlet simonlet commented Mar 31, 2026

Summary

  • Pin all GitHub Actions references to specific SHA commits instead of mutable version tags
  • Prevents supply chain attacks where a tag could be moved to point to malicious code

Test plan

  • Pin and allow pinned version of Core-EDC Github actions from our fork of the Core-EDC .github repo
    • e.g. the hash of the tags: [0.11.1_2025-03-10_2, 0.14.0_2025-08-21_2, 0.15.0_2025-12-05_2]
  • Verify CI workflows still run correctly after the pin

🤖 Generated with Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant