Skip to content

Conversation

@wennergr
Copy link
Contributor

@wennergr wennergr commented Oct 2, 2025

Summary

  • Pin all GitHub Actions to their specific SHA1 hashes to reduce supply chain attack risk
  • Replaces version tags with specific commit SHAs
  • Includes version comments for easier reference
  • Changes generated with the pinact tool

More information: See internal supply-chain-security wiki page

Changes

  • speakeasy-api/sdk-generation-action/.github/workflows/workflow-executor.yaml@v15...@f09110c4676497cba7ef85034a6fb94191f1c417 # v15
  • speakeasy-api/sdk-generation-action/.github/workflows/sdk-publish.yaml@v15...@f09110c4676497cba7ef85034a6fb94191f1c417 # v15

Pin all GitHub Actions to their specific SHA1 hashes to reduce the risk of supply chain attacks. This ensures that the exact version of each action is used and prevents potential malicious updates from automatically being incorporated.
@wennergr wennergr requested review from bgroff and git-phu October 2, 2025 20:44
@wennergr wennergr merged commit 9f75c79 into main Oct 3, 2025
@wennergr wennergr deleted the wennergr/pin-github-actions-sha1 branch October 3, 2025 00:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants