Skip to content

Commit c65e8d4

Browse files
ejahnGithubCopilot
andauthored
Pin GitHub Actions to commit SHAs for security (#386)
Replace mutable tag references with immutable commit SHAs in codeql-analysis.yml and check-dist.yml to prevent supply chain attacks. Actions pinned: - actions/checkout@v6.0.2 - github/codeql-action/init@v4 - github/codeql-action/autobuild@v4 - github/codeql-action/analyze@v4 - actions/setup-node@v6.3.0 - actions/upload-artifact@v7.0.0 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
1 parent ffbe572 commit c65e8d4

File tree

2 files changed

+7
-7
lines changed

2 files changed

+7
-7
lines changed

.github/workflows/check-dist.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -28,11 +28,11 @@ jobs:
2828
steps:
2929
- name: Checkout
3030
id: checkout
31-
uses: actions/checkout@v6.0.2
31+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
3232

3333
- name: Setup Node.js
3434
id: setup-node
35-
uses: actions/setup-node@v6.3.0
35+
uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0
3636
with:
3737
node-version-file: .node-version
3838
cache: npm
@@ -60,7 +60,7 @@ jobs:
6060
- if: ${{ failure() && steps.diff.outcome == 'failure' }}
6161
name: Upload Artifact
6262
id: upload
63-
uses: actions/upload-artifact@v7.0.0
63+
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
6464
with:
6565
name: dist
6666
path: dist/

.github/workflows/codeql-analysis.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -32,19 +32,19 @@ jobs:
3232
steps:
3333
- name: Checkout
3434
id: checkout
35-
uses: actions/checkout@v6.0.2
35+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
3636

3737
- name: Initialize CodeQL
3838
id: initialize
39-
uses: github/codeql-action/init@v4
39+
uses: github/codeql-action/init@38697555549f1db7851b81482ff19f1fa5c4fedc # v4.34.1
4040
with:
4141
languages: ${{ matrix.language }}
4242
source-root: src
4343

4444
- name: Autobuild
4545
id: autobuild
46-
uses: github/codeql-action/autobuild@v4
46+
uses: github/codeql-action/autobuild@38697555549f1db7851b81482ff19f1fa5c4fedc # v4.34.1
4747

4848
- name: Perform CodeQL Analysis
4949
id: analyze
50-
uses: github/codeql-action/analyze@v4
50+
uses: github/codeql-action/analyze@38697555549f1db7851b81482ff19f1fa5c4fedc # v4.34.1

0 commit comments

Comments
 (0)