Skip to content

ci: pin GitHub Actions to commit SHAs#56

Merged
bschimke95 merged 1 commit intomainfrom
KU-5612/pin-actions-to-sha
Apr 8, 2026
Merged

ci: pin GitHub Actions to commit SHAs#56
bschimke95 merged 1 commit intomainfrom
KU-5612/pin-actions-to-sha

Conversation

@louiseschmidtgen
Copy link
Copy Markdown
Contributor

Pin all GitHub Actions to their commit SHAs to improve supply chain security.

This prevents:

  • Compromised tags from injecting malicious code
  • Unexpected behavior from mutable references
  • Supply chain attacks via action tag manipulation

@louiseschmidtgen louiseschmidtgen requested a review from a team as a code owner April 8, 2026 08:19
Copy link
Copy Markdown

@bschimke95 bschimke95 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All pinned SHAs verified against their claimed version tags. Changes are correct and consistent.

@bschimke95 bschimke95 merged commit 4a82ead into main Apr 8, 2026
2 checks passed
@bschimke95 bschimke95 deleted the KU-5612/pin-actions-to-sha branch April 8, 2026 12:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants