Skip to content

[StepSecurity] ci: Harden GitHub Actions#2063

Merged
RalphHightower merged 1 commit intoRalphHightower:mainfrom
step-security-bot:chore/GHA-080451-stepsecurity-remediation
Oct 8, 2025
Merged

[StepSecurity] ci: Harden GitHub Actions#2063
RalphHightower merged 1 commit intoRalphHightower:mainfrom
step-security-bot:chore/GHA-080451-stepsecurity-remediation

Conversation

@step-security-bot
Copy link
Copy Markdown
Contributor

Summary

This pull request is created by StepSecurity at the request of @RalphHightower. Please merge the Pull Request to incorporate the requested changes. Please tag @RalphHightower on your message if you have any questions related to the PR.

Security Fixes

Pinned Dependencies

GitHub Action tags and Docker tags are mutable. This poses a security risk. GitHub's Security Hardening guide recommends pinning actions to full length commit.

Feedback

For bug reports, feature requests, and general feedback; please email support@stepsecurity.io. To create such PRs, please visit https://app.stepsecurity.io/securerepo.

Signed-off-by: StepSecurity Bot bot@stepsecurity.io

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
@RalphHightower RalphHightower added github_actions Pull requests that update GitHub Actions code ossf OpenSSF is a community of software developers and security engineers labels Oct 8, 2025
@RalphHightower RalphHightower self-assigned this Oct 8, 2025
Copy link
Copy Markdown
Owner

@RalphHightower RalphHightower left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@RalphHightower RalphHightower merged commit d7373a6 into RalphHightower:main Oct 8, 2025
4 of 7 checks passed
@RalphHightower RalphHightower added the action – success Successful action label Oct 9, 2025
@github-actions github-actions Bot deleted the chore/GHA-080451-stepsecurity-remediation branch April 19, 2026 07:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action – success Successful action github_actions Pull requests that update GitHub Actions code ossf OpenSSF is a community of software developers and security engineers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants