Skip to content

chore: SECENG-7706 [security] Pin versions of GitHub Actions to full commit hash#43

Merged
jlmitra-ampl merged 1 commit into
mainfrom
jlm-pin-github-actions
Apr 2, 2026
Merged

chore: SECENG-7706 [security] Pin versions of GitHub Actions to full commit hash#43
jlmitra-ampl merged 1 commit into
mainfrom
jlm-pin-github-actions

Conversation

@jlmitra-ampl
Copy link
Copy Markdown
Contributor

@jlmitra-ampl jlmitra-ampl commented Apr 2, 2026

This PR pins versions of GitHub Actions to full commit hash via automated scripts.
In general, this PR doesn't change the behavior of the workflows, so you can merge this safely.

This pull request was created by multi-gitter.

Please merge this pull request by 2026-04-10.

For any questions, please ask in the Slack channel #help-security.


Note

Low Risk
Low risk: workflow changes only pin existing GitHub Action references to immutable commit SHAs; runtime behavior should remain the same aside from fetching a specific action revision.

Overview
Pins GitHub Actions used by CI workflows to full commit SHAs for supply-chain hardening.

Updates build.yml, release.yml, and jira-issue-create.yml to replace floating tags/branches (e.g., @v3, @v4, @master) with specific commit hashes for actions/checkout, actions/setup-go, actions/setup-node, golangci-lint-action, and Atlassian Jira actions.

Written by Cursor Bugbot for commit 8a07629. This will update automatically on new commits. Configure here.

…commit hash

This PR pins versions of GitHub Actions to full commit hash via automated scripts.
In general, this PR doesn't change the behavior of the workflows, so you can merge this safely.

This pull request was created by [multi-gitter](https://github.com/lindell/multi-gitter).

Please merge this pull request by 2026-04-10.

For any questions, please ask in the Slack channel #help-security.
@jlmitra-ampl jlmitra-ampl merged commit 9e81c3e into main Apr 2, 2026
7 checks passed
@jlmitra-ampl jlmitra-ampl deleted the jlm-pin-github-actions branch April 2, 2026 16:37
@github-actions
Copy link
Copy Markdown

🎉 This PR is included in version 1.11.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant