Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

185509385 - Pin GitHub Actions to specific hashes #285

Merged
merged 1 commit into from
Jul 10, 2023

Conversation

nimalank7
Copy link
Contributor

@nimalank7 nimalank7 commented Jul 10, 2023

Description:

  • Currently we pin to versions which means that we automatically pull in the latest changes which presents a security risk as we don't know which code is running in our build pipeline.
  • This PR fixes this by pinning to a specific hash

How to review

Verify that GitHub actions successfully run

Description:
- Currently we pin to versions which means that we automatically pull in the latest changes which presents a security risk as we don't know which code is running in our build pipeline.
- This PR fixes this by pinning to a specific hash
@nimalank7 nimalank7 force-pushed the 185509385-Pin-GitHub-Actions-to-specific-hashes branch from 0c6b6c9 to f694dac Compare July 10, 2023 15:00
Copy link

@fearoffish fearoffish left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nimalank7 nimalank7 merged commit 8f3e731 into main Jul 10, 2023
29 checks passed
@nimalank7 nimalank7 deleted the 185509385-Pin-GitHub-Actions-to-specific-hashes branch July 10, 2023 16:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants