Skip to content

ci: pin GitHub Actions to SHAs #1219

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

nschonni
Copy link
Contributor

@nschonni nschonni commented Mar 24, 2025

Preview Tests

There was a ecosystem issue by tj-actions the other week which caused secrets to be spilled from CI logs. That action didn't affect this repo, but since it is part of the recommended hardening, I run npx pin-github-action .github/workflows/ to pin them. Dependabot should still create PRs to bump them as needed

@howard-e
Copy link
Contributor

@nschonni very interesting! I had only seen this notice in passing but didn't check further.

Thanks for sharing this. As stated, this repo doesn't seem affected but will monitor the discourse around it and see if we should move this forward (or in any other repos, ha)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants