Skip to content
This repository was archived by the owner on Jan 12, 2026. It is now read-only.

switched to hashes, cleaned up actions#297

Merged
acunniffe merged 1 commit intodevelopfrom
fix/secure-actions
Aug 5, 2020
Merged

switched to hashes, cleaned up actions#297
acunniffe merged 1 commit intodevelopfrom
fix/secure-actions

Conversation

@trulyronak
Copy link
Copy Markdown

Done in response to the issue @notnmeyer brought up via https://julienrenaux.fr/2019/12/20/github-actions-security-risk/

What I did

  • went and replaced every single action we used with the corresponding hash for the version we were using)
  • removed unneeded actions

What we can do to be more secure

  • fork each action to opticdev so we can maintain and update them locally (kinda overkill imo, but could be useful if we want to do anything custom)

@trulyronak trulyronak requested a review from notnmeyer August 3, 2020 18:52
@github-actions github-actions Bot added the fix label Aug 3, 2020
Copy link
Copy Markdown
Contributor

@notnmeyer notnmeyer left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeeeeeeeeees 👏

Copy link
Copy Markdown

@ghost ghost left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request has been automatically deployed to FeaturePeek. 💎
Your deployment will be kept up-to-date with this pull request's latest changes.

https://peek.run/61mhgp7l


Please read our docs for more configuration details.

@acunniffe acunniffe merged commit c63fcc5 into develop Aug 5, 2020
@notnmeyer notnmeyer deleted the fix/secure-actions branch February 15, 2021 22:28
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants