Skip to content

[SECENG-364] Pin GitHub Actions to commit SHAs#8

Merged
Stephanie Ginovker (sginovker) merged 1 commit into
masterfrom
security/pin-actions-to-sha
Apr 8, 2026
Merged

[SECENG-364] Pin GitHub Actions to commit SHAs#8
Stephanie Ginovker (sginovker) merged 1 commit into
masterfrom
security/pin-actions-to-sha

Conversation

@sginovker
Copy link
Copy Markdown

@sginovker Stephanie Ginovker (sginovker) commented Apr 8, 2026

Ticket

SECENG-364

Summary

Pin all external GitHub Actions to commit SHAs for supply chain security. Internal (hoverinc/) actions are left unpinned.

Pinned Actions

Dependabot

Added/updated dependabot.yml to keep GitHub Actions pinned to the latest SHA with a 7-day update cooldown.

@sginovker Stephanie Ginovker (sginovker) marked this pull request as ready for review April 8, 2026 17:57
@sginovker Stephanie Ginovker (sginovker) merged commit c378a90 into master Apr 8, 2026
2 checks passed
@sginovker Stephanie Ginovker (sginovker) deleted the security/pin-actions-to-sha branch May 7, 2026 17:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants