Skip to content

[StepSecurity] ci: Harden GitHub Actions tags#27201

Merged
TravisEz13 merged 1 commit into
PowerShell:masterfrom
step-security-bot:chore/GHA-071950-stepsecurity-remediation
Apr 7, 2026
Merged

[StepSecurity] ci: Harden GitHub Actions tags#27201
TravisEz13 merged 1 commit into
PowerShell:masterfrom
step-security-bot:chore/GHA-071950-stepsecurity-remediation

Conversation

@step-security-bot

Copy link
Copy Markdown
Contributor

Summary

This pull request is created by StepSecurity at the request of @TravisEz13. Please merge the Pull Request to incorporate the requested changes. Please tag @TravisEz13 on your message if you have any questions related to the PR.

Security Fixes

Pinned Dependencies

GitHub Action tags and Docker tags are mutable. This poses a security risk. GitHub's Security Hardening guide recommends pinning actions to full length commit.

Feedback

For bug reports, feature requests, and general feedback; please email support@stepsecurity.io. To create such PRs, please visit https://app.stepsecurity.io/securerepo.

Signed-off-by: StepSecurity Bot bot@stepsecurity.io

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
@step-security-bot step-security-bot requested review from a team and jshigetomi as code owners April 7, 2026 19:51
@TravisEz13 TravisEz13 added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Apr 7, 2026
@TravisEz13 TravisEz13 enabled auto-merge (squash) April 7, 2026 19:58
@TravisEz13 TravisEz13 changed the title [StepSecurity] ci: Harden GitHub Actions [StepSecurity] ci: Harden GitHub Actions tags Apr 7, 2026
@TravisEz13 TravisEz13 merged commit 34375e9 into PowerShell:master Apr 7, 2026
44 of 45 checks passed
daxian-dbw pushed a commit to daxian-dbw/PowerShell that referenced this pull request Apr 9, 2026
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
daxian-dbw added a commit to daxian-dbw/PowerShell that referenced this pull request Apr 9, 2026
daxian-dbw pushed a commit to daxian-dbw/PowerShell that referenced this pull request Apr 9, 2026
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
daxian-dbw pushed a commit to daxian-dbw/PowerShell that referenced this pull request Apr 9, 2026
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
daxian-dbw pushed a commit to daxian-dbw/PowerShell that referenced this pull request Apr 9, 2026
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
daxian-dbw pushed a commit to daxian-dbw/PowerShell that referenced this pull request Apr 9, 2026
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
JustinGrote pushed a commit to JustinGrote/PowerShell that referenced this pull request Jun 2, 2026
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Backport-7.4.x-Done Backport-7.5.x-Done Backport-7.6.x-Done CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants