Skip to content

chore(): pin GitHub Actions to commit SHAs#9

Merged
stairsj merged 1 commit intomainfrom
chore/stairsj/pin-github-actions
Mar 23, 2026
Merged

chore(): pin GitHub Actions to commit SHAs#9
stairsj merged 1 commit intomainfrom
chore/stairsj/pin-github-actions

Conversation

@stairsj
Copy link
Copy Markdown
Contributor

@stairsj stairsj commented Mar 23, 2026

Pin GitHub Actions to commit SHAs

Description of change

Pins all third-party GitHub Actions to specific commit SHAs to protect
against tag hijacking / supply chain attacks. Actions from the rewindio
org are excluded and remain at their original version refs.

Uses ratchet for SHA resolution.

Testing Performed

@stairsj stairsj requested a review from a team as a code owner March 23, 2026 18:22
@stairsj stairsj self-assigned this Mar 23, 2026
@stairsj stairsj requested review from dnorth98, kevintylerstark and phamtriduy and removed request for a team March 23, 2026 18:22
@stairsj stairsj merged commit 067f756 into main Mar 23, 2026
4 checks passed
@stairsj stairsj deleted the chore/stairsj/pin-github-actions branch March 23, 2026 18:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants