Skip to content

ci: pin github actions hashes#3

Merged
mbaraniak-exodus merged 1 commit intoexodusfrom
mbaraniak/github-action-pinning
May 1, 2026
Merged

ci: pin github actions hashes#3
mbaraniak-exodus merged 1 commit intoexodusfrom
mbaraniak/github-action-pinning

Conversation

@mbaraniak-exodus
Copy link
Copy Markdown

📝 Summary

This PR pins third-party GitHub Actions to full commit SHAs.
Internal ExodusMovement/... actions are out of scope for this campaign and are intentionally not locked in these changes.
This removes floating action references and reduces supply-chain risk by ensuring workflow execution uses reviewed, immutable upstream revisions instead of tags that can be moved.

Copy link
Copy Markdown

@ale-exo ale-exo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utACK

  • https://github.com/actions/checkout/releases/tag/v4.3.1
  • https://github.com/actions/setup-node/releases/tag/v4.4.0

@mbaraniak-exodus mbaraniak-exodus merged commit a1e8382 into exodus May 1, 2026
2 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants