Skip to content

chore: SECENG-7706 [security] Pin versions of GitHub Actions to full commit hash (fix)#301

Merged
aliaksandr-kazarez merged 1 commit into
mainfrom
jlm-pin-github-actions-fix
Apr 8, 2026
Merged

chore: SECENG-7706 [security] Pin versions of GitHub Actions to full commit hash (fix)#301
aliaksandr-kazarez merged 1 commit into
mainfrom
jlm-pin-github-actions-fix

Conversation

@jlmitra-ampl

@jlmitra-ampl jlmitra-ampl commented Apr 7, 2026

Copy link
Copy Markdown
Contributor

This PR pins versions of GitHub Actions to full commit hash via automated scripts.
This PR fixes issues with previous script versions which skipped actions wrapped in "" quotation marks.
In general, this PR doesn't change the behavior of the workflows, so you can merge this safely.

Please merge this pull request by 2026-04-10.

For any questions, please ask in the Slack channel #help-security.


Note

Low Risk
Low risk: this is a GitHub Actions dependency pin intended to be behavior-preserving, with only a small chance of breaking if the pinned commit differs from the tag or is removed.

Overview
Updates .github/workflows/release.yml to pin lannonbr/repo-permission-check-action from the 2.0.2 tag to the corresponding full commit SHA, improving supply-chain integrity without intended workflow behavior changes.

Reviewed by Cursor Bugbot for commit 82c9a9c. Bugbot is set up for automated code reviews on this repo. Configure here.

@aliaksandr-kazarez aliaksandr-kazarez merged commit 2df8801 into main Apr 8, 2026
7 checks passed
@aliaksandr-kazarez aliaksandr-kazarez deleted the jlm-pin-github-actions-fix branch April 8, 2026 04:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants