Skip to content

Why do we use a commit hash instead of a version for the tibdex/github-app-token github action? #3342

Closed Answered by dkershner6
dkershner6 asked this question in Q&A
Discussion options

You must be logged in to vote

Via @mrgrain

For this highly security relevant action that is published by a more or less random user, we've always felt it would be better to use a specific vetted commit.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@dkershner6
Comment options

Answer selected by dkershner6
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant