Skip to content

chore: SECENG-7706 [security] Pin versions of GitHub Actions to full commit hash - quotation fix#44

Merged
jlmitra-ampl merged 1 commit into
mainfrom
jlm-gha-pin-fix
Apr 7, 2026
Merged

chore: SECENG-7706 [security] Pin versions of GitHub Actions to full commit hash - quotation fix#44
jlmitra-ampl merged 1 commit into
mainfrom
jlm-gha-pin-fix

Conversation

@jlmitra-ampl
Copy link
Copy Markdown
Contributor

@jlmitra-ampl jlmitra-ampl commented Apr 7, 2026

This PR pins versions of GitHub Actions to full commit hash via automated scripts.
This PR fixes an error with the previous script not correctly parsing lines in "" quotations.
In general, this PR doesn't change the behavior of the workflows, so you can merge this safely.

This pull request was created by multi-gitter.

Please merge this pull request by 4/10/2026.

For any questions, please ask in the Slack channel #help-security.


Note

Low Risk
Low risk: this is a dependency pin in a GitHub Actions workflow and should not change behavior beyond ensuring the action version is immutable.

Overview
Updates .github/workflows/release.yml to use a fully pinned commit SHA for lannonbr/repo-permission-check-action (with an inline note for 2.0.2) instead of the mutable 2.0.2 tag.

Reviewed by Cursor Bugbot for commit 8f69936. Bugbot is set up for automated code reviews on this repo. Configure here.

…commit hash - quotation fix

This PR pins versions of GitHub Actions to full commit hash via [automated scripts](https://github.com/amplitude/tools/tree/master/seceng/github_actions/pin-gha).
This PR fixes an error with the previous script not correctly parsing lines in "" quotations.
In general, this PR doesn't change the behavior of the workflows, so you can merge this safely.

This pull request was created by [multi-gitter](https://github.com/lindell/multi-gitter).

Please merge this pull request by 4/10/2026.

For any questions, please ask in the Slack channel #help-security.
@jlmitra-ampl jlmitra-ampl merged commit 692a70c into main Apr 7, 2026
7 checks passed
@jlmitra-ampl jlmitra-ampl deleted the jlm-gha-pin-fix branch April 7, 2026 21:09
@github-actions
Copy link
Copy Markdown

🎉 This PR is included in version 1.11.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant