Skip to content

[SEC-7924] chore: pin third-party GitHub Actions to commit SHAs#152

Merged
pkaeding merged 1 commit intomainfrom
security/SEC-7924/pin-github-actions
Apr 1, 2026
Merged

[SEC-7924] chore: pin third-party GitHub Actions to commit SHAs#152
pkaeding merged 1 commit intomainfrom
security/SEC-7924/pin-github-actions

Conversation

@pkaeding
Copy link
Copy Markdown
Contributor

@pkaeding pkaeding commented Mar 31, 2026

Pin all third-party GitHub Actions to full-length commit SHAs to prevent supply chain attacks. Addresses findings from the
third-party-action-not-pinned-to-commit-sha Semgrep rule.


Related Jira issue: SEC-7924: Unpinned GitHub Actions remediation

Pin all third-party GitHub Actions to full-length commit SHAs to prevent
supply chain attacks. Addresses findings from the
third-party-action-not-pinned-to-commit-sha Semgrep rule.
@pkaeding pkaeding requested review from a team and cspath1 March 31, 2026 22:59
@pkaeding pkaeding merged commit 4bbf755 into main Apr 1, 2026
5 checks passed
@pkaeding pkaeding deleted the security/SEC-7924/pin-github-actions branch April 1, 2026 16:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants