Skip to content

security: pin GitHub Actions to commit SHAs#2

Merged
slackstat merged 1 commit into
mainfrom
fix/pin-action-shas
Feb 23, 2026
Merged

security: pin GitHub Actions to commit SHAs#2
slackstat merged 1 commit into
mainfrom
fix/pin-action-shas

Conversation

@slackstat

Copy link
Copy Markdown
Owner

Summary

  • Pin actions/checkout and softprops/action-gh-release to immutable commit SHAs instead of mutable version tags
  • Prevents supply chain attacks where a tag could be moved to point at malicious code

@slackstat slackstat merged commit 34cb1d3 into main Feb 23, 2026
1 check passed
@slackstat slackstat deleted the fix/pin-action-shas branch February 23, 2026 18:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant