Skip to content

ci: pin GitHub Actions to commit SHAs#20

Merged
bschimke95 merged 1 commit intomainfrom
KU-5612/pin-actions-to-sha
Apr 9, 2026
Merged

ci: pin GitHub Actions to commit SHAs#20
bschimke95 merged 1 commit intomainfrom
KU-5612/pin-actions-to-sha

Conversation

@louiseschmidtgen
Copy link
Copy Markdown
Contributor

Pin all GitHub Actions to their commit SHAs to improve supply chain security.

This prevents:

  • Compromised tags from injecting malicious code
  • Unexpected behavior from mutable references
  • Supply chain attacks via action tag manipulation

Related: KU-5612

@bschimke95 bschimke95 merged commit d88630c into main Apr 9, 2026
5 of 6 checks passed
@bschimke95 bschimke95 deleted the KU-5612/pin-actions-to-sha branch April 9, 2026 11:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants