Skip to content

ci: pin third-party actions to commit-hash#315

Merged
Eomm merged 1 commit into
mainfrom
ci/tp-actions
Jun 19, 2025
Merged

ci: pin third-party actions to commit-hash#315
Eomm merged 1 commit into
mainfrom
ci/tp-actions

Conversation

@Fdawgs

@Fdawgs Fdawgs commented Jun 16, 2025

Copy link
Copy Markdown
Member

Closes https://github.com/fastify/website/security/code-scanning/10 and 5 other code scanning alerts.

Most first-party actions now use https://github.com/actions/publish-immutable-action, which negates the need for commit hashes, but this is not available for third-party actions yet.

@Eomm Eomm merged commit ca21a24 into main Jun 19, 2025
6 of 7 checks passed
@Eomm Eomm deleted the ci/tp-actions branch June 19, 2025 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants