Skip to content

[grace-hopper-day] Pin Github Actions by commit-hash - nodejs/help #1108

Closed
@RafaelGSS

Description

@RafaelGSS

Pin Actions to a full length commit SHA

Repository: https://github.com/nodejs/help

Why is this needed?

Before and After the fix

Before the fix, your workflow may look like this (use of v1 and latest tags)

After the fix, Secure-Repo pins each Action and docker image to an immutable checksum.

Pull request example: electron/electron#36343

In this pull request, the workflow file has the GitHub Actions tags pinned automatically to their full-length commit SHA.

Screenshot of Action pinned to commit SHA


From: https://github.com/step-security/secure-repo#3-pin-actions-to-a-full-length-commit-sha

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions