Skip to content

Pin GitHub Actions dependencies to specific commit hashes#194

Merged
krororo merged 1 commit intokufu:masterfrom
krororo:pin-github-actions
Mar 19, 2025
Merged

Pin GitHub Actions dependencies to specific commit hashes#194
krororo merged 1 commit intokufu:masterfrom
krororo:pin-github-actions

Conversation

@krororo
Copy link
Copy Markdown
Collaborator

@krororo krororo commented Mar 19, 2025

GitHub Actions from tags/branches to full commit hashes for improved security.

see: https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066

@krororo krororo marked this pull request as ready for review March 19, 2025 01:26
@auto-assign auto-assign bot requested review from osyo-manga and yono March 19, 2025 01:26
Copy link
Copy Markdown
Contributor

@mkmn mkmn left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@krororo krororo merged commit 3871200 into kufu:master Mar 19, 2025
12 checks passed
@krororo krororo deleted the pin-github-actions branch March 19, 2025 01:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants