fix: pin GitHub Actions to SHA hashes #64
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🔒 Security: Pin GitHub Actions to SHA hashes
This PR pins GitHub Actions to their SHA hashes to improve security by preventing potential supply chain attacks through tag mutation.
Task: DX-1985
One-Pager: Automatic SHA Pinner One-Pager
📊 Summary
📝 Changes Made
.github/workflows/ci.ymldtolnay/rust-toolchain@v1→dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9Swatinem/rust-cache@v2→Swatinem/rust-cache@f13886b937689c021905a6b90929199931d60db1.github/workflows/publish.ymldtolnay/rust-toolchain@v1→dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9🔍 Why this change?
Pinning GitHub Actions to SHA hashes instead of tags provides:
🧪 Testing
❓ Questions?
If you have any questions about this change, feel free to ask the dev-ex team in #notify-dev-ex.
📚 References
🤖 This PR was automatically generated by the SHA Pinner Audit tool.