Skip to content

docs(actions): add SHA pinning notes to OIDC examples#45002

Open
happysnaker wants to merge 1 commit into
github:mainfrom
happysnaker:docs/oidc-sha-pinning-comments
Open

docs(actions): add SHA pinning notes to OIDC examples#45002
happysnaker wants to merge 1 commit into
github:mainfrom
happysnaker:docs/oidc-sha-pinning-comments

Conversation

@happysnaker

Copy link
Copy Markdown

Summary

  • add the SHA pinning comment reusable to OIDC workflow examples that already use full commit SHAs for third-party actions
  • keep the existing third-party action notice and example structure unchanged
  • make the guidance consistent across the Google Cloud Platform, AWS, Azure, HashiCorp Vault, and PyPI OIDC pages

Closes #34316

@github-actions github-actions Bot added the triage Do not begin working on this issue until triaged by the team label Jun 30, 2026
@github-actions

Copy link
Copy Markdown
Contributor

How to review these changes 👓

Thank you for your contribution. To review these changes, choose one of the following options:

A Hubber will need to deploy your changes internally to review.

Table of review links

Note: Please update the URL for your staging server or codespace.

The table shows the files in the content directory that were changed in this pull request. This helps you review your changes on a staging server. Changes to the data directory are not included in this table.

Source Review Production What Changed
actions/how-tos/secure-your-work/security-harden-deployments/oidc-in-aws.md fpt
ghec
ghes@ 3.21 3.20 3.19 3.18 3.17
fpt
ghec
ghes@ 3.21 3.20 3.19 3.18 3.17
actions/how-tos/secure-your-work/security-harden-deployments/oidc-in-azure.md fpt
ghec
ghes@ 3.21 3.20 3.19 3.18 3.17
fpt
ghec
ghes@ 3.21 3.20 3.19 3.18 3.17
actions/how-tos/secure-your-work/security-harden-deployments/oidc-in-google-cloud-platform.md fpt
ghec
ghes@ 3.21 3.20 3.19 3.18 3.17
fpt
ghec
ghes@ 3.21 3.20 3.19 3.18 3.17
actions/how-tos/secure-your-work/security-harden-deployments/oidc-in-hashicorp-vault.md fpt
ghec
ghes@ 3.21 3.20 3.19 3.18 3.17
fpt
ghec
ghes@ 3.21 3.20 3.19 3.18 3.17
actions/how-tos/secure-your-work/security-harden-deployments/oidc-in-pypi.md fpt
ghec
fpt
ghec

Key: fpt: Free, Pro, Team; ghec: GitHub Enterprise Cloud; ghes: GitHub Enterprise Server

🤖 This comment is automatically generated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

triage Do not begin working on this issue until triaged by the team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OIDC examples don't pin external actions (& don't declare them)

1 participant