-
-
Notifications
You must be signed in to change notification settings - Fork 3.7k
Pinning GitHub Actions #3708
Copy link
Copy link
Open
Labels
Build Automationgithub_actionsPull requests that update GitHub Actions codePull requests that update GitHub Actions code
Metadata
Metadata
Assignees
Labels
Build Automationgithub_actionsPull requests that update GitHub Actions codePull requests that update GitHub Actions code
Type
Fields
Give feedbackNo fields configured for issues without a type.
tl;dr: No, we are waiting for https://github.blog/news-insights/product-news/whats-coming-to-our-github-actions-2026-security-roadmap/
Given that we do not create releases using actions, sign artifacts in actions or upload to public nuget.org (no secrets), this is not considered a security problem.