Skip to content

GitHub Actions: Pin actions to SHA hashes#95

Merged
bshand merged 1 commit intomainfrom
feature/pin_github_actions
Apr 14, 2026
Merged

GitHub Actions: Pin actions to SHA hashes#95
bshand merged 1 commit intomainfrom
feature/pin_github_actions

Conversation

@bshand
Copy link
Copy Markdown
Contributor

@bshand bshand commented Apr 14, 2026

Ensure that all active GitHub actions on the pseudonymisation_service repository are pinned to SHA hashes.
Add dependabot checks for GitHub Actions.
This is to reduce the risk of supply chain attacks, cf. https://docs.github.com/en/actions/reference/security/secure-use#using-third-party-actions

Disable Slack notifications from GitHub Actions

GitHub Actions: Disable Slack notifications
Add dependabot checks for GitHub Actions
@bshand bshand merged commit 21c36f5 into main Apr 14, 2026
6 checks passed
@bshand bshand deleted the feature/pin_github_actions branch April 14, 2026 08:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant