Skip to content

Use Commit Hashes to Version Reusable Github Actions Tasks #165

@sarina

Description

@sarina

In response to https://www.bleepingcomputer.com/news/security/supply-chain-attack-on-popular-github-action-exposes-ci-cd-secrets/ we should move to pinning GitHub Action versions by commit hash.

Some resources:

Metadata

Metadata

Assignees

Labels

securityRelates to improving to the security posture of the platform

Type

No type

Projects

Status

Todo

Status

📋 Backlog

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions