Commit 61f2542
committed
fix: update README.md file to list explicit secure practices to apply
Update README.md to explictly list secure practices for updating GItHub
Actions taken from GitHub security documentation and examples from a few
security blogs.
When GeoNet migrated to GitHub Actions it was noted at the time to use
the full-length commit SHA value to securely use external 3rd-party code
to avoid the sort of supply chain attaks seen with Trivy scanner and
malicious overwriting of all version tags for Trivy scanner GitHub actions.1 parent ef64c8f commit 61f2542
4 files changed
Lines changed: 1359 additions & 1266 deletions
0 commit comments