fix(ci): pin tj-actions/changed-files to SHA and bump Node to 20#56
fix(ci): pin tj-actions/changed-files to SHA and bump Node to 20#56
Conversation
Pin tj-actions/changed-files from v46 tag to commit SHA to prevent supply chain attacks. Bump Node.js from EOL 18 to 20 in js-lint workflow. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
Latest scan for commit: Security Scan ResultsScan Metadata
SummaryScanner ResultsThe table below shows findings by scanner, with status based on severity thresholds and dependencies: Column Explanations: Severity Levels (S/C/H/M/L/I):
Other Columns:
Scanner Results:
Severity Thresholds (Thresh Column):
Threshold Source: Values in parentheses indicate where the threshold is configured:
Statistics calculation:
Detailed FindingsShow 6 actionable findingsFinding 1: GHSA-mrrh-fwg8-r2c3-tj-actions/changed-files
Description: Finding 2: GHSA-mrrh-fwg8-r2c3-tj-actions/changed-files
Description: Finding 3: GHSA-mrrh-fwg8-r2c3-tj-actions/changed-files
Description: Finding 4: GHSA-mcph-m25j-8j63-tj-actions/changed-files
Description: Finding 5: GHSA-mcph-m25j-8j63-tj-actions/changed-files
Description: Finding 6: GHSA-mcph-m25j-8j63-tj-actions/changed-files
Description: Report generated by Automated Security Helper (ASH) at 2026-03-10T20:09:32+00:00 |
Summary
tj-actions/changed-filesto commit SHA (ed68ef82c095e0d48ec87eccea555d944a631a4c) in 3 workflows (js-lint,python-lint,ash-security-scan) to prevent supply chain attacks if thev46tag is movedjs-lint.yml— Node 18 reached EOL in April 2025Test plan
js-lintworkflow runs successfully on a PR with JS/TS changespython-lintworkflow runs successfully on a PR with Python changesash-security-scanworkflow runs successfully on a PR with relevant file changes🤖 Generated with Claude Code