Skip to content

ci: pin GitHub Actions to full commit SHA#33

Closed
qtipbera wants to merge 1 commit into
mainfrom
ci/pin-actions-to-sha
Closed

ci: pin GitHub Actions to full commit SHA#33
qtipbera wants to merge 1 commit into
mainfrom
ci/pin-actions-to-sha

Conversation

@qtipbera

@qtipbera qtipbera commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

SHA-pin all actions. Mutable tags can be force-pushed if an action repo is compromised, and evaporate if it is disabled (cf. Azure/functions-action, Jun 5 Miasma). Stopgap ahead of Renovate digest maintenance. Ref: Miasma scan 2026-06-09.

@qtipbera qtipbera requested a review from a team as a code owner June 9, 2026 16:00
@qtipbera qtipbera added the security Security hardening label Jun 9, 2026
@qtipbera qtipbera closed this Jun 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Security hardening

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant