Skip to content

Use sha pinning for third party github actions #2689

@riccardobl

Description

@riccardobl

To reduce the attack surface for supply-chain attacks, we should use SHA commit pinning for third-party / non official github actions and make dependabot work with them.

Official and widely used actions should still retain the semantic versions for dependabot vulnerability scanner to work better.

Metadata

Metadata

Labels

buildscriptAn issue with the buildscript

Type

No type

Projects

Status

tracked

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions