Skip to content

Pin 3rd-party actions to SHA1#35

Open
fbricon wants to merge 1 commit intoredhat-developer:masterfrom
fbricon:pin-actions-sha1
Open

Pin 3rd-party actions to SHA1#35
fbricon wants to merge 1 commit intoredhat-developer:masterfrom
fbricon:pin-actions-sha1

Conversation

@fbricon
Copy link
Collaborator

@fbricon fbricon commented Jan 24, 2023

Hi!

Following the GH Action Security Hardening guide we should use the commit SHA instead of the branch or tag for any third-party untrusted action.

This PR was submitted by a script.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant