fix: pin GitHub Actions to SHA hashes #7
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🔒 Security: Pin GitHub Actions to SHA hashes
This PR pins GitHub Actions to their SHA hashes to improve security by preventing potential supply chain attacks through tag mutation.
Task: DX-1985
One-Pager: Automatic SHA Pinner One-Pager
📊 Summary
📝 Changes Made
.github/workflows/release.ymlsemantic-release-action/github-actions/semantic-release@v5→semantic-release-action/github-actions/semantic-release@6c14113c1273619fccad11d7638b2c9e985e9085🔍 Why this change?
Pinning GitHub Actions to SHA hashes instead of tags provides:
🧪 Testing
❓ Questions?
If you have any questions about this change, feel free to ask the dev-ex team in #notify-dev-ex.
📚 References
🤖 This PR was automatically generated by the SHA Pinner Audit tool.