Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: pin all non-docker/non-GH action versions #316

Merged
merged 1 commit into from
Mar 20, 2025

Conversation

HalosGhost
Copy link
Collaborator

This avoids the issue of malleable version tags in the event of repo compromise.

Note that this leaves the tagged versions from official GH/docker actions out of a hope to minimize churn/maintenance-burden.

Includes a NEWS post.

cf. https://www.cve.org/CVERecord?id=CVE-2025-30066

This avoids the issue of malleable version tags in the event of repo
compromise.

Note that this leaves the tagged versions from official GH/docker
actions out of a hope to minimize churn/maintenance-burden.

Includes a NEWS post.

cf. https://www.cve.org/CVERecord?id=CVE-2025-30066

Signed-off-by: Sam Stuewe <[email protected]>
@HalosGhost HalosGhost requested a review from maurermi March 19, 2025 18:45
Copy link
Collaborator

@maurermi maurermi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ACK; Pins a few workflows to stable versions, looks like they all passed in CI so this should be good to go in.

@HalosGhost
Copy link
Collaborator Author

All builds and runs fine for me as well, so I'm calling it good.

@HalosGhost HalosGhost merged commit 8444ef8 into mit-dci:trunk Mar 20, 2025
7 checks passed
@HalosGhost HalosGhost deleted the chore/pin-actions branch March 20, 2025 13:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants