Skip to content

Pin GitHub Actions to commit SHAs for supply chain security#7

Closed
jzyinq wants to merge 1 commit intomasterfrom
feature/ARCH-884-github-action-sha-pin
Closed

Pin GitHub Actions to commit SHAs for supply chain security#7
jzyinq wants to merge 1 commit intomasterfrom
feature/ARCH-884-github-action-sha-pin

Conversation

@jzyinq
Copy link
Contributor

@jzyinq jzyinq commented Jan 30, 2026

Summary

Pin external GitHub Actions from tags to commit SHAs for supply chain security.

Changes

Replace tag references with full commit SHA hashes.

Affected actions:

  • actions/checkout@v4
  • astral-sh/setup-uv@v6
  • docker/build-push-action@v6
  • docker/login-action@v3
  • docker/metadata-action@v5
  • docker/setup-buildx-action@v3

@jzyinq jzyinq requested a review from glothriel as a code owner January 30, 2026 09:24
@jzyinq jzyinq closed this Feb 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant