Skip to content

Commit 7581641

Browse files
sionsmithclaude
andcommitted
fix: pin GitHub Actions to immutable commit SHAs
Mitigates supply chain attacks via tag mutation (CVE-2025-30066) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1 parent de6261b commit 7581641

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

.github/workflows/generate.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,8 @@ jobs:
2020
generate:
2121
runs-on: ubuntu-latest
2222
steps:
23-
- uses: actions/checkout@v4
24-
- uses: actions/setup-node@v4
23+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
24+
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
2525
with:
2626
node-version: 22
2727
cache: npm
@@ -51,7 +51,7 @@ jobs:
5151
5252
- name: Create PR
5353
if: steps.diff.outputs.changed == 'true'
54-
uses: peter-evans/create-pull-request@v6
54+
uses: peter-evans/create-pull-request@c5a7806660adbe173f04e3e038b0ccdcd758773c # v6
5555
with:
5656
branch: chore/regenerate-types
5757
commit-message: "chore: regenerate types from updated OpenAPI spec"

0 commit comments

Comments
 (0)