Skip to content

SEC-704: Pin all nonlocal actions#30

Merged
whrazer merged 1 commit into
mainfrom
azer/pin-actions
Jun 18, 2025
Merged

SEC-704: Pin all nonlocal actions#30
whrazer merged 1 commit into
mainfrom
azer/pin-actions

Conversation

@whrazer

@whrazer whrazer commented Jun 16, 2025

Copy link
Copy Markdown
Contributor

https://front.atlassian.net/browse/SEC-704
Now that we have allowlisted all existing GH actions, we should work to pin all to a full length SHA commit as a security measure in response to the tj-actions incident.

Safe to revert.

This major upgrade has been done before without issue, expect low risk.

@whrazer whrazer merged commit 42dbe52 into main Jun 18, 2025
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants