Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pin external GitHub Actions to hashes #99

Merged
merged 2 commits into from
Dec 13, 2022
Merged

Pin external GitHub Actions to hashes #99

merged 2 commits into from
Dec 13, 2022

Conversation

dbanck
Copy link
Member

@dbanck dbanck commented Dec 13, 2022

The intention here is to reduce the security risk posed by the supply chain - i.e. externally maintained GitHub Actions.

This also adds dependabot for checking for action updates.

@dbanck dbanck added the dependencies Auto-pinning label Dec 13, 2022
@dbanck dbanck requested a review from jpogran December 13, 2022 15:10
@dbanck dbanck merged commit 94179fd into main Dec 13, 2022
@dbanck dbanck deleted the ci-pin-gh-actions branch December 13, 2022 16:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Auto-pinning
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants