Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ghat #319

Closed
wants to merge 2 commits into from
Closed

Ghat #319

wants to merge 2 commits into from

Conversation

jackdawm
Copy link
Contributor

@jackdawm jackdawm commented Aug 2, 2023

What was changed

Used ghat locally to fetch the commit SHA of the latest version of all actions in all workflows.

Why?

Github's security hardening recommendations for actions include pinning actions to a full length commit SHA.

How did you test it?

Looked at the workflow logs on this PR.

Potential risks
The pinned commit SHAs here seem to be version jumps, so these actions might not work as intended.

@jackdawm jackdawm marked this pull request as ready for review August 2, 2023 18:49
@jackdawm jackdawm closed this Aug 3, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant