Skip to content

ci: pin github action with full-length commit hash#40

Closed
ostk0069 wants to merge 1 commit intopantsbuild:mainfrom
ostk0069:ci-update-pin-with-commit-hash
Closed

ci: pin github action with full-length commit hash#40
ostk0069 wants to merge 1 commit intopantsbuild:mainfrom
ostk0069:ci-update-pin-with-commit-hash

Conversation

@ostk0069
Copy link
Copy Markdown

@ostk0069 ostk0069 commented Nov 26, 2025

In order to enable Require actions to be pinned to a full-length commit SHA setting, this diff is necessary.

@ostk0069
Copy link
Copy Markdown
Author

@jsirois Could you please review this?

@jsirois
Copy link
Copy Markdown
Contributor

jsirois commented Nov 27, 2025

@ostk0069 I am no longer a committer in this org; so I'm not sure if sha pinning is what is desired. You probably want @benjyw , @sureshjoshi or @tdyas to take a look.

@benjyw benjyw requested a review from sureshjoshi November 28, 2025 20:47
@ostk0069
Copy link
Copy Markdown
Author

ostk0069 commented Dec 1, 2025

@sureshjoshi I need your review, please.

@sureshjoshi
Copy link
Copy Markdown
Member

Thanks for the PR @ostk0069.

We haven't yet agreed to require SHA pinning (something we'd likely roll out across all repos together).

At the moment, the approach I tend to take is to pin major (or major.minor) versions of the platform provider (i.e. GitHub), and then SHA pin basically everyone else.

That meets a reasonable security risk-reward tolerance (to me, anyways).

However, this PR did point out that we don't have Dependabot running here to handle these upgrade reminders, so I went ahead and opened #41.

Thanks for the reminder.

@sureshjoshi sureshjoshi closed this Dec 1, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants