Skip to content

ci: pin GitHub Actions to commit SHAs#67

Merged
fguillot merged 1 commit intomainfrom
ci/pin-actions-to-sha
Apr 22, 2026
Merged

ci: pin GitHub Actions to commit SHAs#67
fguillot merged 1 commit intomainfrom
ci/pin-actions-to-sha

Conversation

@fguillot
Copy link
Copy Markdown
Member

Replaces mutable tag/branch refs with immutable commit SHAs to guard against supply-chain attacks via compromised tags. Original version is retained as a trailing comment so Dependabot can still bump them.

Replaces mutable tag/branch refs with immutable commit SHAs to guard
against supply-chain attacks via compromised tags. Original version is
retained as a trailing comment so Dependabot can still bump them.
@fguillot fguillot merged commit 12a48e4 into main Apr 22, 2026
11 checks passed
@fguillot fguillot deleted the ci/pin-actions-to-sha branch April 22, 2026 04:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant