Skip to content

[StepSecurity] ci: Harden GitHub Actions#705

Merged
RalphHightower merged 1 commit intoRalphHightower:mainfrom
step-security-bot:stepsecurity_remediation_1737092125
Jan 17, 2025
Merged

[StepSecurity] ci: Harden GitHub Actions#705
RalphHightower merged 1 commit intoRalphHightower:mainfrom
step-security-bot:stepsecurity_remediation_1737092125

Conversation

@step-security-bot
Copy link
Copy Markdown
Contributor

Summary

This pull request is created by StepSecurity at the request of @RalphHightower. Please merge the Pull Request to incorporate the requested changes. Please tag @RalphHightower on your message if you have any questions related to the PR.

Security Fixes

Pinned Dependencies

GitHub Action tags and Docker tags are mutable. This poses a security risk. GitHub's Security Hardening guide recommends pinning actions to full length commit.

Feedback

For bug reports, feature requests, and general feedback; please email [email protected]. To create such PRs, please visit https://app.stepsecurity.io/securerepo.

Signed-off-by: StepSecurity Bot [email protected]

@RalphHightower RalphHightower self-assigned this Jan 17, 2025
@RalphHightower RalphHightower added the step-security Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner label Jan 17, 2025
@RalphHightower RalphHightower merged commit de5a2cc into RalphHightower:main Jan 17, 2025
Copy link
Copy Markdown
Owner

@RalphHightower RalphHightower left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@RalphHightower RalphHightower added the action – failure Failure during an Action label Jan 19, 2025
@github-actions github-actions bot deleted the stepsecurity_remediation_1737092125 branch September 14, 2025 06:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action – failure Failure during an Action step-security Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants