Skip to content

CI: pin GitHub Actions workflows#3548

Merged
BethanyG merged 1 commit into
mainfrom
pin-github-action-workflows
Nov 14, 2023
Merged

CI: pin GitHub Actions workflows#3548
BethanyG merged 1 commit into
mainfrom
pin-github-action-workflows

Conversation

@ErikSchierboom
Copy link
Copy Markdown
Member

This PR updates GitHub Actions workflows to a specific version.
This ensures that the workflow will always run the same code, which makes your build stable.
It will also prevent a potential security issue where a tag could be replaced by a malicious commit without consumers being aware of it.

The PR updates each non-SHA based workflow reference with the SHA of the referenced version/tag, so the current behavior should not change.

See https://exercism.org/docs/building/github/gha-best-practices#h-pin-actions-to-shas for more information.

@ErikSchierboom ErikSchierboom added the x:size/tiny Tiny amount of work label Nov 14, 2023
Copy link
Copy Markdown
Member

@BethanyG BethanyG left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍🏽

@BethanyG BethanyG merged commit e3a189c into main Nov 14, 2023
@BethanyG BethanyG deleted the pin-github-action-workflows branch November 14, 2023 14:11
petrem pushed a commit to petrem/exercism--python that referenced this pull request Dec 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

x:size/tiny Tiny amount of work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants