Commit a20ffa2
authored
fix: pin third-party actions and trust docker publisher (#891)
## Summary
- Pin `dorny/paths-filter`, `softprops/action-gh-release`, and
`peter-evans/repository-dispatch` to full commit SHAs for supply chain
security
- Add `docker` to `TRUSTED_PUBLISHERS` in `scripts/audit_actions.ts` so
`docker/*` actions are accepted with tag-only pins
## Test Plan
- `deno fmt --check`, `deno lint`, and `deno run test` all pass
- CI security review should no longer flag unpinned third-party actions1 parent c0abc5a commit a20ffa2
3 files changed
+4
-3
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
| 25 | + | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
143 | 143 | | |
144 | 144 | | |
145 | 145 | | |
146 | | - | |
| 146 | + | |
147 | 147 | | |
148 | 148 | | |
149 | 149 | | |
| |||
159 | 159 | | |
160 | 160 | | |
161 | 161 | | |
162 | | - | |
| 162 | + | |
163 | 163 | | |
164 | 164 | | |
165 | 165 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
58 | 58 | | |
59 | 59 | | |
60 | 60 | | |
| 61 | + | |
61 | 62 | | |
62 | 63 | | |
63 | 64 | | |
| |||
0 commit comments