Skip to content

chore: pin GitHub Actions to immutable commit SHAs#592

Merged
JaimeSeqLabs merged 1 commit intomasterfrom
notask/pin-github-actions-sha
Mar 25, 2026
Merged

chore: pin GitHub Actions to immutable commit SHAs#592
JaimeSeqLabs merged 1 commit intomasterfrom
notask/pin-github-actions-sha

Conversation

@JaimeSeqLabs
Copy link
Contributor

Summary

  • Pin all GitHub Actions references across 5 workflow files to full commit SHAs instead of mutable tags
  • Follows supply chain security best practices for GitHub Actions
  • Includes # ratchet: comments for automated version tracking (compatible with Dependabot/Renovate)

Notes

  • jreleaser/release-action@v2 was pointing to a mutable branch, now pinned to tag 2.5.0
  • jenschelkopf/issue-label-notification-action and ewels/rich-codex are unverified third-party actions — may need review by the security team

Comply with Seqera supply chain security policy. Includes ratchet-style comments for automated version tracking.
@JaimeSeqLabs JaimeSeqLabs merged commit c92bbff into master Mar 25, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants