Skip to content

Use Commit Hashes to Version Reusable Github Actions Tasks #165

@sarina

Description

@sarina

In response to https://www.bleepingcomputer.com/news/security/supply-chain-attack-on-popular-github-action-exposes-ci-cd-secrets/ we should move to pinning GitHub Action versions by commit hash.

Some resources:

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityRelates to improving to the security posture of the platform

    Type

    No type

    Projects

    Status

    Todo

    Status

    🆕 New

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions