Skip to content

chore(): pin GitHub Actions to commit SHAs#3

Merged
stairsj merged 1 commit into
masterfrom
chore/stairsj/pin-github-actions
Mar 24, 2026
Merged

chore(): pin GitHub Actions to commit SHAs#3
stairsj merged 1 commit into
masterfrom
chore/stairsj/pin-github-actions

Conversation

@stairsj
Copy link
Copy Markdown

@stairsj stairsj commented Mar 23, 2026

Pin GitHub Actions to commit SHAs

Description of change

Pins all third-party GitHub Actions to specific commit SHAs to protect
against tag hijacking / supply chain attacks. Actions from the rewindio
org are excluded and remain at their original version refs.

Uses ratchet for SHA resolution.

Testing Performed

@stairsj stairsj self-assigned this Mar 23, 2026
@stairsj stairsj enabled auto-merge (squash) March 23, 2026 20:00
@stairsj stairsj merged commit 5568df3 into master Mar 24, 2026
17 of 20 checks passed
@stairsj stairsj deleted the chore/stairsj/pin-github-actions branch March 24, 2026 13:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants