Skip to content

Conversation

@xopham
Copy link

@xopham xopham commented Feb 5, 2025

  • Add dependabot for github actions
  • Pin actions by hash

Pinning 3rd-party GitHub Actions by commit SHA makes them less vulnerable to compromise of the 3rd party. To avoid outdating and non-verbosity, versions are commented after the SHA and updating via dependabot is introduced that will automatically update the commented version tag as well.

In case of a false commit SHA, this change could break the corresponding workflow. Typically, this does not cause major interruptions, but it can for example affect a release pipeline and require restart causing delays.

@xopham xopham requested a review from a team as a code owner February 5, 2025 14:42
@xopham xopham requested review from lievan and taegyunkim February 5, 2025 14:42
@brettlangdon brettlangdon added the no-changelog This does not need a user visible changelog label Feb 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog This does not need a user visible changelog

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants