Skip to content

Harden example workflows for supply chain security#32

Merged
dash14 merged 1 commit intomainfrom
security/harden-example-workflows
Apr 5, 2026
Merged

Harden example workflows for supply chain security#32
dash14 merged 1 commit intomainfrom
security/harden-example-workflows

Conversation

@dash14
Copy link
Copy Markdown
Owner

@dash14 dash14 commented Apr 5, 2026

Summary

  • Pin third-party actions by commit hash (docker/setup-buildx-action, docker/build-push-action) in example workflows
  • Add fork guard step to prevent accidental execution of dash14's actions after forking
  • Add comments guiding self-hosting replacement and recommending commit hash pinning for direct usage

- Pin third-party actions by commit hash (docker/setup-buildx-action, docker/build-push-action) in example workflows
- Add fork guard step to prevent accidental execution of dash14's actions after forking
- Add comments guiding self-hosting replacement and recommending commit hash pinning for direct usage
@dash14 dash14 merged commit 0d6d430 into main Apr 5, 2026
6 checks passed
@dash14 dash14 deleted the security/harden-example-workflows branch April 5, 2026 12:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant