Skip to content

Conversation

@TohaUA
Copy link

@TohaUA TohaUA commented Nov 28, 2025

Automated pinning of GitHub Actions to their commit SHAs.

This improves security by preventing supply chain attacks through compromised action tags.
Each action is pinned to its current commit SHA with a comment showing the original version.

Related Ticket

https://getpantheon.atlassian.net/browse/DELENG-235

Need Help?

If you have questions or need help, ask in Slack #ask-delivery-engineering

@TohaUA TohaUA requested a review from a team as a code owner November 28, 2025 08:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants