Skip to content

chore(ci): pin all external actions to commit SHAs (PLATL-406)#1

Draft
nielsn wants to merge 1 commit intomainfrom
PLATL-406/sha-versioned-external-actions
Draft

chore(ci): pin all external actions to commit SHAs (PLATL-406)#1
nielsn wants to merge 1 commit intomainfrom
PLATL-406/sha-versioned-external-actions

Conversation

@nielsn
Copy link
Copy Markdown

@nielsn nielsn commented Mar 23, 2026

Summary

  • Pin all third-party GitHub Actions to their commit SHAs for supply-chain security
  • Each pinned action includes a version comment for readability (e.g., # v4)

Why

Mutable tag references (e.g., @v4) can be overwritten — pinning to commit SHAs ensures reproducible, tamper-resistant CI builds.

Test plan

  • Verify all workflows still pass on this branch

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant