Skip to content

Conversation

@adegeo
Copy link
Contributor

@adegeo adegeo commented Oct 30, 2020

It's possible that an action being referenced gets updated and malicious code entered into it. Because we generally reference actions by tags, the owner of a github repository can replace the tag with any commit. Instead of referencing tags, we should reference the commit. This way the codebase cannot change from under us.

@adegeo adegeo merged commit e762a2f into master Nov 2, 2020
@adegeo adegeo deleted the adegeo-actions branch November 2, 2020 21:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants