Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(ci): lockdown untrusted workflows to sha #130

Merged

Conversation

heitorlessa
Copy link
Contributor

@heitorlessa heitorlessa commented Jul 24, 2022

Issue number: #129

Summary

Changes

Please provide a summary of what's being changed

Syncs up security workflow created in Python to enforce untrusted GitHub Actions workflows fail CI.

Tasks:

  • upgrade setup-python to v4
  • upgrade checkout action to v3
  • use untrusted workflows with sha
  • create workflow to lockdown untrusted workflows to sha

User experience

Please share what the user experience looks like before and after this change

Checklist

Please leave checklist items unchecked if they do not apply to your change.

Is this a breaking change?

RFC issue number:

Checklist:

  • Migration process documented
  • Implement warnings (if it can live side by side)

Acknowledgment

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

Disclaimer: We value your time and bandwidth. As such, any pull requests created on non-triaged issues might not be successful.

Signed-off-by: heitorlessa <lessa@amazon.co.uk>
Signed-off-by: heitorlessa <lessa@amazon.co.uk>
Signed-off-by: heitorlessa <lessa@amazon.co.uk>
@auto-assign auto-assign bot requested a review from amirkaws July 24, 2022 12:53
@sliedig sliedig self-requested a review July 24, 2022 13:08
@sliedig sliedig merged commit bb63e04 into aws-powertools:develop Jul 24, 2022
@heitorlessa heitorlessa deleted the chore/enforce-github-actions-sha branch July 24, 2022 13:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants