Skip to content

[Aikido] AI Fix for 3rd party Github Actions should be pinned - #19

Merged
mgeier merged 2 commits into
mainfrom
fix/aikido-security-sast-126687507-6yrd
Sep 28, 2026
Merged

mgeier merged 2 commits into
mainfrom
fix/aikido-security-sast-126687507-6yrd

Conversation

@aikido-autofix

Copy link
Copy Markdown
Contributor

This patch mitigates a potential supply chain attack by pinning the version of third-party Github Actions to their commit SHA.

✅ 9 issues fixed by this PR
Issue Severity           Description
Sast#747577379
HIGH
A third-party GitHub Action was imported, and is not pinned via a hash. This leaves your CI/CD at risk for potential supply chain attacks, if the affected GitHub Action is compromised.
Sast#747577384
HIGH
A third-party GitHub Action was imported, and is not pinned via a hash. This leaves your CI/CD at risk for potential supply chain attacks, if the affected GitHub Action is compromised.
Sast#747577392
HIGH
A third-party GitHub Action was imported, and is not pinned via a hash. This leaves your CI/CD at risk for potential supply chain attacks, if the affected GitHub Action is compromised.
Sast#747577398
HIGH
A third-party GitHub Action was imported, and is not pinned via a hash. This leaves your CI/CD at risk for potential supply chain attacks, if the affected GitHub Action is compromised.
Sast#747577403
HIGH
A third-party GitHub Action was imported, and is not pinned via a hash. This leaves your CI/CD at risk for potential supply chain attacks, if the affected GitHub Action is compromised.
Sast#747577405
HIGH
A third-party GitHub Action was imported, and is not pinned via a hash. This leaves your CI/CD at risk for potential supply chain attacks, if the affected GitHub Action is compromised.
Sast#747577409
HIGH
A third-party GitHub Action was imported, and is not pinned via a hash. This leaves your CI/CD at risk for potential supply chain attacks, if the affected GitHub Action is compromised.
Sast#747577414
HIGH
A third-party GitHub Action was imported, and is not pinned via a hash. This leaves your CI/CD at risk for potential supply chain attacks, if the affected GitHub Action is compromised.
Sast#747577421
HIGH
A third-party GitHub Action was imported, and is not pinned via a hash. This leaves your CI/CD at risk for potential supply chain attacks, if the affected GitHub Action is compromised.

High confidence: Aikido has a robust set of benchmarks for similar fixes, and they are proven to be effective.

@aikido-autofix aikido-autofix Bot added the security Label created by Aikido AutoFix label Sep 28, 2026
@mgeier

mgeier commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

I have added a commit for proper handling of rust-toolchain: 67d1e18

@mgeier
mgeier merged commit 15f057d into main Sep 28, 2026
5 checks passed
@mgeier
mgeier deleted the fix/aikido-security-sast-126687507-6yrd branch September 28, 2026 08:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Label created by Aikido AutoFix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants