Skip to content

chore: SECENG-7706 [security] Pin versions of GitHub Actions to full commit hash#81

Open
jlmitra-ampl wants to merge 1 commit intomainfrom
jlm-pin-github-actions
Open

chore: SECENG-7706 [security] Pin versions of GitHub Actions to full commit hash#81
jlmitra-ampl wants to merge 1 commit intomainfrom
jlm-pin-github-actions

Conversation

@jlmitra-ampl
Copy link
Copy Markdown

@jlmitra-ampl jlmitra-ampl commented Apr 2, 2026

This PR pins versions of GitHub Actions to full commit hash via automated scripts.
In general, this PR doesn't change the behavior of the workflows, so you can merge this safely.

This pull request was created by multi-gitter.

Please merge this pull request by 2026-04-10.

For any questions, please ask in the Slack channel #help-security.


Note

Low Risk
Low risk because this only pins GitHub Actions used in workflows to specific commit hashes; behavior should remain the same aside from consuming those exact action revisions.

Overview
Pins all third-party GitHub Actions in the jira-issue-create, lint, test, and release workflows from floating refs (e.g., @master/version tags) to specific commit SHAs.

This hardens CI/CD against upstream action changes and supply-chain risk without changing the workflows’ intended steps or configuration.

Written by Cursor Bugbot for commit 7bf1c0f. This will update automatically on new commits. Configure here.

…commit hash

This PR pins versions of GitHub Actions to full commit hash via automated scripts.
In general, this PR doesn't change the behavior of the workflows, so you can merge this safely.

This pull request was created by [multi-gitter](https://github.com/lindell/multi-gitter).

Please merge this pull request by 2026-04-10.

For any questions, please ask in the Slack channel #help-security.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant