Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GitHub actions need to be pinned to a SHA1 #89

Open
Stebalien opened this issue Mar 26, 2021 · 2 comments
Open

GitHub actions need to be pinned to a SHA1 #89

Stebalien opened this issue Mar 26, 2021 · 2 comments
Assignees
Labels
team/ipdx Notify IP Developer Experience team

Comments

@Stebalien
Copy link
Member

https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#using-third-party-actions

@mikeal
Copy link
Contributor

mikeal commented Mar 27, 2021

We should do this for all the Actions we pull from third parties. But for the actions we maintain we should use master or a release branch because managing the updates across so many repos will be too painful.

@galargh galargh added the team/ipdx Notify IP Developer Experience team label Apr 14, 2022
@laurentsenta
Copy link

(triage session)
We want to come up with a way to track where this rule is implemented or violated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
team/ipdx Notify IP Developer Experience team
Projects
None yet
Development

No branches or pull requests

4 participants