Skip to content

security: pin GitHub Actions to SHA1 for supply chain security

5eba1a3
Select commit
Loading
Failed to load commit list.
Closed

Pin GitHub Actions to SHA1 for supply chain security #432

security: pin GitHub Actions to SHA1 for supply chain security
5eba1a3
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL failed Oct 3, 2025 in 3s

1 new alert including 1 high severity security vulnerability

New alerts in code changed by this pull request

Security Alerts:

  • 1 high

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 26 in .github/workflows/create-oss-pr-snapshot-in-cloud.yml

See this annotation in the file changed.

Code scanning / CodeQL

Checkout of untrusted code in trusted context High

Potential execution of untrusted code on a privileged workflow (
issue_comment
)