Skip to content

Commit d5f1297

Browse files
authoredFeb 28, 2023
Pin Token Exchange Workflow Version (#106)
This reduces our security risk
1 parent 8ad5cac commit d5f1297

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed
 

‎.github/workflows/release.yaml

+3-3
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
steps:
2626
- name: Generate token
2727
id: generate_token
28-
uses: tibdex/github-app-token@v1
28+
uses: tibdex/github-app-token@b62528385c34dbc9f38e5f4225ac829252d1ea92
2929
with:
3030
app_id: ${{env.APP_ID}}
3131
private_key: ${{ secrets.TOKEN_EXCHANGE_GH_APP_PRIVATE_KEY }}
@@ -59,7 +59,7 @@ jobs:
5959
steps:
6060
- name: Generate token
6161
id: generate_token
62-
uses: tibdex/github-app-token@v1
62+
uses: tibdex/github-app-token@b62528385c34dbc9f38e5f4225ac829252d1ea92
6363
with:
6464
app_id: ${{env.APP_ID}}
6565
private_key: ${{ secrets.TOKEN_EXCHANGE_GH_APP_PRIVATE_KEY }}
@@ -88,7 +88,7 @@ jobs:
8888
steps:
8989
- name: Generate token
9090
id: generate_token
91-
uses: tibdex/github-app-token@v1
91+
uses: tibdex/github-app-token@b62528385c34dbc9f38e5f4225ac829252d1ea92
9292
with:
9393
app_id: ${{env.APP_ID}}
9494
private_key: ${{ secrets.TOKEN_EXCHANGE_GH_APP_PRIVATE_KEY }}

0 commit comments

Comments
 (0)
Please sign in to comment.