Skip to content

Conversation

@corneliusludmann
Copy link
Contributor

Pin all external GitHub Actions to specific commit SHAs for supply chain security.

Changes

  • actions/checkout@v4 → pinned to SHA
  • actions/setup-node@v4 → pinned to SHA
  • docker/build-push-action@v6 → pinned to SHA
  • filiptronicek/get-last-job-status@main → pinned to SHA
  • google-github-actions/auth@v2 → pinned to SHA
  • google-github-actions/setup-gcloud@v2 → pinned to SHA
  • rtCamp/action-slack-notify@v2 → pinned to SHA

Related

Pin all external GitHub Actions to specific commit SHAs to prevent
supply chain attacks via malicious tag updates.

Actions pinned:
- actions/checkout@v4
- actions/setup-node@v4
- docker/build-push-action@v6
- filiptronicek/get-last-job-status@main
- google-github-actions/auth@v2
- google-github-actions/setup-gcloud@v2
- rtCamp/action-slack-notify@v2

Part of PDE-138
Closes PDE-221

Co-authored-by: Ona <[email protected]>
@corneliusludmann corneliusludmann marked this pull request as ready for review December 10, 2025 11:27
@corneliusludmann corneliusludmann merged commit c4bb23f into master Dec 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants