Skip to content

Pin GitHub Actions to specific SHAs (33 actions in 7 files)#19

Merged
ddk-dbt merged 1 commit into
masterfrom
pin-github-actions-1761853929075
Oct 31, 2025
Merged

Pin GitHub Actions to specific SHAs (33 actions in 7 files)#19
ddk-dbt merged 1 commit into
masterfrom
pin-github-actions-1761853929075

Conversation

@ddk-dbt
Copy link
Copy Markdown

@ddk-dbt ddk-dbt commented Oct 30, 2025

📌 Pin GitHub Actions to Specific SHAs

This PR updates GitHub Actions references from tags/branches to specific commit SHAs for improved security and reproducibility.

📊 Summary

  • Files changed: 7
  • Actions pinned: 33

📝 Changes by file

.github/workflows/jira_close.yml

  • 📌 actions/checkout@v4actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4
  • 📌 atlassian/gajira-login@masteratlassian/gajira-login@c22a5debd482401472b285de4f6deedf70ddbb92 # atlassian/gajira-login@master

.github/workflows/changelog.yml

  • 📌 actions/checkout@v3actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # actions/checkout@v3

.github/workflows/snyk-pr.yml

  • 📌 actions/checkout@v4actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4
  • 📌 actions/checkout@v4actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4

.github/workflows/jira_comment.yml

  • 📌 atlassian/gajira-login@masteratlassian/gajira-login@c22a5debd482401472b285de4f6deedf70ddbb92 # atlassian/gajira-login@master
  • 📌 atlassian/gajira-comment@masteratlassian/gajira-comment@b296309a56fe4764d3eb2ef21cb86770fcb9f621 # atlassian/gajira-comment@master

.github/workflows/jira_issue.yml

  • 📌 actions/checkout@v4actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4
  • 📌 atlassian/gajira-login@v2.0.0atlassian/gajira-login@90a599561baaf8c05b080645ed73db7391c246ed # atlassian/gajira-login@v2.0.0
  • 📌 atlassian/gajira-create@v2.0.1atlassian/gajira-create@c0a9c69ac9d6aa063fed57201e55336ada860183 # atlassian/gajira-create@v2.0.1

.github/workflows/build-test.yml

  • 📌 actions/checkout@v4actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4
  • 📌 actions/setup-go@v5actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # actions/setup-go@v5
  • 📌 golangci/golangci-lint-action@v7golangci/golangci-lint-action@9fae48acfc02a90574d7c304a1758ef9895495fa # golangci/golangci-lint-action@v7
  • 📌 actions/checkout@v4actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4
  • 📌 actions/setup-go@v5actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # actions/setup-go@v5
  • 📌 codecov/test-results-action@v1codecov/test-results-action@47f89e9acb64b76debcd5ea40642d25a4adced9f # codecov/test-results-action@v1
  • 📌 codecov/codecov-action@v5codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # codecov/codecov-action@v5
  • 📌 actions/checkout@v4actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4
  • 📌 actions/setup-go@v5actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # actions/setup-go@v5
  • 📌 actions/checkout@v4actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4
  • 📌 actions/setup-go@v5actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # actions/setup-go@v5
  • 📌 codecov/test-results-action@v1codecov/test-results-action@47f89e9acb64b76debcd5ea40642d25a4adced9f # codecov/test-results-action@v1
  • 📌 codecov/codecov-action@v5codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # codecov/codecov-action@v5
  • 📌 actions/checkout@v4actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4
  • 📌 actions/setup-go@v5actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # actions/setup-go@v5
  • 📌 actions/checkout@v4actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4
  • 📌 actions/setup-go@v5actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # actions/setup-go@v5
  • 📌 actions/setup-python@v5actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # actions/setup-python@v5
  • 📌 codecov/test-results-action@v1codecov/test-results-action@47f89e9acb64b76debcd5ea40642d25a4adced9f # codecov/test-results-action@v1
  • 📌 codecov/codecov-action@v5codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # codecov/codecov-action@v5
  • 📌 actions/checkout@v4actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4
  • 📌 actions/setup-go@v5actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # actions/setup-go@v5

.github/workflows/snyk-issue.yml

  • 📌 actions/checkout@v4actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # actions/checkout@v4

Updated action references from tags/branches to specific commit SHAs for improved security and reproducibility.
@ddk-dbt ddk-dbt merged commit f2ab60f into master Oct 31, 2025
7 of 39 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 31, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant