Skip to content

Conversation

@Fdawgs
Copy link
Contributor

@Fdawgs Fdawgs commented Mar 25, 2025

What this does:

Follow the recent compromise of tj-actions/changed-files, this PR pins GitHub actions to specific commit hashes to ensure a known version of each action is used, mitigating the risk of a supply chain attack through malicious updates.

See related blog post by rafaelgss about pinning to the commit-hash.

Related issues:

n/a

Pre/Post merge checklist:

  • Update change log

@dhensby
Copy link
Collaborator

dhensby commented Mar 25, 2025

Thanks for this, I had followed this incident and was thinking this would be a good idea, so thanks for putting in the effort and getting it done 💪

@dhensby dhensby merged commit e62de1b into tediousjs:master Mar 25, 2025
45 checks passed
@Fdawgs Fdawgs deleted the ci/pin branch March 25, 2025 10:16
@github-actions
Copy link

🎉 This PR is included in version 12.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants