Skip to content

[PD1-951] Pin all GitHub Actions#2

Merged
alok27a merged 1 commit intomainfrom
gha-pin
Mar 30, 2026
Merged

[PD1-951] Pin all GitHub Actions#2
alok27a merged 1 commit intomainfrom
gha-pin

Conversation

@joshuanapoli
Copy link
Copy Markdown
Member

Summary

  • Pin all GitHub Actions to their full commit SHA to mitigate supply-chain attacks
  • Each pinned action includes a version comment for readability (e.g., # v4.3.1)

Test plan

  • Verify CI workflows still pass with pinned action SHAs
  • Confirm all action references resolve correctly

🤖 Generated with Claude Code

Pin all GitHub Actions to their full commit SHA to reduce the risk
of supply-chain attacks in the GitHub Actions ecosystem.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@joshuanapoli joshuanapoli requested a review from alok27a March 30, 2026 14:20
@gemini-code-assist
Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

Copy link
Copy Markdown
Contributor

@alok27a alok27a left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated build passed. Approving.

@alok27a alok27a merged commit e36f99b into main Mar 30, 2026
11 checks passed
@alok27a alok27a deleted the gha-pin branch March 30, 2026 14:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants