Skip to content

chore: pin all GitHub Actions to commit SHAs#57

Merged
0x46616c6b merged 1 commit into
mainfrom
chore/pin-gha-to-sha
Apr 7, 2026
Merged

chore: pin all GitHub Actions to commit SHAs#57
0x46616c6b merged 1 commit into
mainfrom
chore/pin-gha-to-sha

Conversation

@0x46616c6b

Copy link
Copy Markdown
Contributor

Summary

  • Pin all GitHub Actions references from version tags to full commit SHAs for improved supply chain security
  • Prevents potential tag manipulation attacks by referencing immutable commit hashes
  • Original version tags are preserved as inline comments for readability

Pinned Actions

Action Version SHA
Staffbase/gha-workflows (automerge) v12.0.1 963c984d
Staffbase/gha-workflows (release) v9.2.0 e8d36c17
cla-assistant/github-action v2.6.1 ca4a40a7
actions/setup-node v5 a0853c24
actions/setup-python v6 a309ff8b

The changes and the PR were generated by OpenCode.

Pin all GitHub Actions references from version tags to full commit
SHAs for improved supply chain security. The original version tags are
preserved as inline comments for readability.

Co-Authored-By: OpenCode <noreply@opencode.ai>
@0x46616c6b 0x46616c6b marked this pull request as ready for review April 2, 2026 07:04
@0x46616c6b 0x46616c6b requested review from a team, pymnh and weizenspreu April 2, 2026 07:04
@0x46616c6b 0x46616c6b merged commit e492ee3 into main Apr 7, 2026
10 checks passed
@0x46616c6b 0x46616c6b deleted the chore/pin-gha-to-sha branch April 7, 2026 12:09
@github-actions github-actions Bot locked and limited conversation to collaborators Apr 7, 2026
@0x46616c6b 0x46616c6b added the chore Pull requests that are chores label Apr 7, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

chore Pull requests that are chores

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant