Skip to content

Use commit SHA for ALL github actions, except the ones provided by Github (actions/*) #1769

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
pragmaticivan opened this issue Apr 12, 2025 · 3 comments
Labels
enhancement New feature or request

Comments

@pragmaticivan
Copy link
Member

Is your feature request related to a problem? Please describe.
For security reasons and to avoid situations like the ones in tj-actions, I would recommend we use commit SHA for most actions. Dependabot supports tag updates as a comment already and there should be no major issues on that support.

@pragmaticivan pragmaticivan added the enhancement New feature or request label Apr 12, 2025
@tylerbenson
Copy link
Member

I'm not familiar... what happened to them?

@pragmaticivan
Copy link
Member Author

@tylerbenson
Copy link
Member

Thanks. We can also point out that this is the recommended practice by Github.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants