Skip to content

Pin GitHub actions to commit-hash #4342

Closed
@Fdawgs

Description

@Fdawgs

Follow the recent compromise of tj-actions/changed-files, it would be a good idea to pin GitHub actions in this repo to specific commit hashes to ensure a known version of each action is used, mitigating the risk of a supply chain attack through malicious updates.

See related blog post by rafaelgss about pinning to the commit-hash.

Happy to make a PR for this.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions