Skip to content

Conversation

@MariusStorhaug
Copy link
Member

The GitHub-Script action is now pinned to a specific SHA version for improved security and consistency.

Pin GitHub-Script action

Updated the action reference from version tag to specific SHA:

  • PSModule/GitHub-Script2010983167dc7a41bcd84cb88e698ec18eccb7ca (v1.7.8)

This ensures the action version is locked and cannot be changed without updating the SHA, preventing supply chain attacks.

@MariusStorhaug MariusStorhaug self-assigned this Jan 22, 2026
@MariusStorhaug MariusStorhaug marked this pull request as ready for review January 22, 2026 15:31
@MariusStorhaug MariusStorhaug merged commit d75bdec into main Jan 22, 2026
16 of 18 checks passed
@MariusStorhaug MariusStorhaug deleted the patch/pin-github-script-action branch January 22, 2026 15:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Patch]: Pin GitHub-Script action to specific version

2 participants