Skip to content
This repository was archived by the owner on May 21, 2026. It is now read-only.

CLOUD-410 ktlo: pin GitHub actions to commit SHAs#7

Merged
ebruatjimdo merged 2 commits into
masterfrom
ktlo/pin-gh-actions
May 21, 2026
Merged

CLOUD-410 ktlo: pin GitHub actions to commit SHAs#7
ebruatjimdo merged 2 commits into
masterfrom
ktlo/pin-gh-actions

Conversation

@desouradeep
Copy link
Copy Markdown
Contributor

@desouradeep desouradeep commented May 12, 2026

Action required from the owning team: please review and merge this PR. It was opened as part of an org-wide rollout for CLOUD-410; the Cloud team is not merging on your behalf.

Summary

Pins all external GitHub Actions in this repo from mutable tags (e.g. @v4) to immutable commit SHAs, and ensures dependabot is configured to keep them updated.

Improves supply-chain security per CLOUD-410. Each pinned line keeps the original tag as a trailing comment for readability.

  • Jimdo-owned actions (Jimdo/…) are intentionally not pinned (out of scope per the ticket).
  • Local actions (./...) are untouched.
  • Dependabot is configured (or updated) to track github-actions monthly, on the 1st of each month, at a hour staggered between 09:00–15:00 Europe/Berlin (one fixed hour per repo). A 3-day cooldown filters out brand-new releases.

Test plan

  • CI passes
  • No unintended changes outside .github/

@desouradeep desouradeep added the cloud-410 CLOUD-410: pin GitHub actions to commit SHAs label May 12, 2026
@desouradeep desouradeep changed the title ktlo: pin GitHub actions to commit SHAs CLOUD-410 ktlo: pin GitHub actions to commit SHAs May 12, 2026
@desouradeep desouradeep marked this pull request as ready for review May 13, 2026 11:19
@ebruatjimdo ebruatjimdo merged commit 383d921 into master May 21, 2026
1 check passed
@ebruatjimdo ebruatjimdo deleted the ktlo/pin-gh-actions branch May 21, 2026 17:09
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

cloud-410 CLOUD-410: pin GitHub actions to commit SHAs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants