Skip to content

[StepSecurity] ci: Harden GitHub Actions#816

Merged
RalphHightower merged 1 commit intoRalphHightower:mainfrom
step-security-bot:stepsecurity_remediation_1738704707
Feb 4, 2025
Merged

[StepSecurity] ci: Harden GitHub Actions#816
RalphHightower merged 1 commit intoRalphHightower:mainfrom
step-security-bot:stepsecurity_remediation_1738704707

Conversation

@step-security-bot
Copy link
Copy Markdown
Contributor

Summary

This pull request is created by StepSecurity at the request of @RalphHightower. Please merge the Pull Request to incorporate the requested changes. Please tag @RalphHightower on your message if you have any questions related to the PR.

Security Fixes

Pinned Dependencies

GitHub Action tags and Docker tags are mutable. This poses a security risk. GitHub's Security Hardening guide recommends pinning actions to full length commit.

Feedback

For bug reports, feature requests, and general feedback; please email support@stepsecurity.io. To create such PRs, please visit https://app.stepsecurity.io/securerepo.

Signed-off-by: StepSecurity Bot bot@stepsecurity.io

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Copy link
Copy Markdown
Owner

@RalphHightower RalphHightower left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@RalphHightower RalphHightower merged commit 7b0b499 into RalphHightower:main Feb 4, 2025
@RalphHightower RalphHightower added the step-security Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner label Feb 4, 2025
@github-actions github-actions Bot deleted the stepsecurity_remediation_1738704707 branch September 14, 2025 06:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

step-security Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants