Skip to content

[FEATURE]: Pin 3rd party github action to commit SHAs #16041

@sidpalas

Description

@sidpalas

Feature hasn't been suggested before.

  • I have verified this feature I'm about to request hasn't been suggested before.

Describe the enhancement you want to request

Pinning actions to specific commit hashes protects against supply chain attacks (e.g. https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066).

It is easy to accomplish with tooling like https://github.com/mheap/pin-github-action and improves the security posture of the repo

Metadata

Metadata

Assignees

Labels

coreAnything pertaining to core functionality of the application (opencode server stuff)discussionUsed for feature requests, proposals, ideas, etc. Open discussion

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions