Skip to content

chore(): pin GitHub Actions to commit SHAs#29

Merged
stairsj merged 1 commit intomainfrom
chore/stairsj/pin-github-actions
Mar 23, 2026
Merged

chore(): pin GitHub Actions to commit SHAs#29
stairsj merged 1 commit intomainfrom
chore/stairsj/pin-github-actions

Conversation

@stairsj
Copy link
Copy Markdown
Contributor

@stairsj stairsj commented Mar 23, 2026

Pin GitHub Actions to commit SHAs

Description of change

Pins all third-party GitHub Actions to specific commit SHAs to protect
against tag hijacking / supply chain attacks. Actions from the rewindio
org are excluded and remain at their original version refs.

Uses ratchet for SHA resolution.

Testing Performed

@stairsj stairsj self-assigned this Mar 23, 2026
@stairsj stairsj requested a review from a team as a code owner March 23, 2026 18:22
@github-actions
Copy link
Copy Markdown

Simplecov Report

Covered Threshold
72.72% 70%

@stairsj stairsj merged commit 69cd444 into main Mar 23, 2026
7 checks passed
@stairsj stairsj deleted the chore/stairsj/pin-github-actions branch March 23, 2026 18:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants