Skip to content

ci: pin third-party GitHub actions to immutable commit SHAs (OpenSSF Scorecard) - #114

Open
emirhan-karaca wants to merge 1 commit into
mat:masterfrom
emirhan-karaca:security/pin-actions-openssf
Open

emirhan-karaca wants to merge 1 commit into
mat:masterfrom
emirhan-karaca:security/pin-actions-openssf

Conversation

@emirhan-karaca

Copy link
Copy Markdown

Why this change is important

According to the OpenSSF Scorecard and SLSA Framework, referencing third-party GitHub Actions via mutable release tags (such as @v4 or @v5) introduces a supply-chain security vulnerability. If an upstream tag is maliciously moved or modified, arbitrary code can execute in your CI/CD environment.

What this PR does

  • Pins all third-party GitHub Actions to immutable full 40-character commit hashes.
  • Preserves the original human-readable version tags as inline comments for easy tracking:
    \\diff
    • uses: actions/checkout@v4
  • Zero breaking changes to the build, test, or release pipelines.
  • Preserves all existing YAML comments, spacing, and formatting.

Generated with action-pin.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant