Skip to content

[StepSecurity] ci: Harden GitHub Actions#703

Merged
RalphHightower merged 1 commit intoRalphHightower:mainfrom
step-security-bot:stepsecurity_remediation_1737082923
Jan 17, 2025
Merged

[StepSecurity] ci: Harden GitHub Actions#703
RalphHightower merged 1 commit intoRalphHightower:mainfrom
step-security-bot:stepsecurity_remediation_1737082923

Conversation

@step-security-bot
Copy link
Copy Markdown
Contributor

Summary

This pull request is created by StepSecurity at the request of @RalphHightower. Please merge the Pull Request to incorporate the requested changes. Please tag @RalphHightower on your message if you have any questions related to the PR.

Security Fixes

Pinned Dependencies

GitHub Action tags and Docker tags are mutable. This poses a security risk. GitHub's Security Hardening guide recommends pinning actions to full length commit.

Feedback

For bug reports, feature requests, and general feedback; please email [email protected]. To create such PRs, please visit https://app.stepsecurity.io/securerepo.

Signed-off-by: StepSecurity Bot [email protected]

Copy link
Copy Markdown
Owner

@RalphHightower RalphHightower left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@RalphHightower RalphHightower merged commit 06a57aa into RalphHightower:main Jan 17, 2025
@RalphHightower RalphHightower added ossf OpenSSF is a community of software developers and security engineers action – failure Failure during an Action labels Jan 17, 2025
@github-actions github-actions bot deleted the stepsecurity_remediation_1737082923 branch September 14, 2025 06:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action – failure Failure during an Action ossf OpenSSF is a community of software developers and security engineers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants