Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

github: Pin external GitHub Actions to hashes #575

Merged
merged 2 commits into from
Jan 30, 2023
Merged

Conversation

radeksimko
Copy link
Member

@radeksimko radeksimko commented Dec 19, 2022

The intention here is to reduce the security risk posed by the supply chain - i.e. externally maintained GitHub Actions.


Note that I also bumped the major versions of both Actions, which should not make a visible difference. I believe the main reason for the major bump was NodeJS version, where the old version either already is or soon will be EOL anyway, so this is somewhat necessary and optimistic step.

@radeksimko radeksimko requested a review from a team December 19, 2022 20:25
@radeksimko radeksimko merged commit ccff1a9 into main Jan 30, 2023
@radeksimko radeksimko deleted the ci-pin-gh-actions branch January 30, 2023 09:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants