-
-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Use sha pinning for third party github actions #2689
Copy link
Copy link
Closed
Labels
buildscriptAn issue with the buildscriptAn issue with the buildscript
Description
To reduce the attack surface for supply-chain attacks, we should use SHA commit pinning for third-party / non official github actions and make dependabot work with them.
Official and widely used actions should still retain the semantic versions for dependabot vulnerability scanner to work better.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
buildscriptAn issue with the buildscriptAn issue with the buildscript
Type
Projects
Status
tracked