Skip to content

SEC-704: Pin all nonlocal actions #30

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jun 18, 2025
Merged

SEC-704: Pin all nonlocal actions #30

merged 1 commit into from
Jun 18, 2025

Conversation

whrazer
Copy link
Contributor

@whrazer whrazer commented Jun 16, 2025

https://front.atlassian.net/browse/SEC-704
Now that we have allowlisted all existing GH actions, we should work to pin all to a full length SHA commit as a security measure in response to the tj-actions incident.

Safe to revert.

This major upgrade has been done before without issue, expect low risk.

@whrazer whrazer merged commit 42dbe52 into main Jun 18, 2025
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants