Skip to content

Pin GH Actions to commit sha#683

Open
thomasferrandiz wants to merge 1 commit intomasterfrom
pin-actions-to-sha
Open

Pin GH Actions to commit sha#683
thomasferrandiz wants to merge 1 commit intomasterfrom
pin-actions-to-sha

Conversation

@thomasferrandiz
Copy link
Copy Markdown
Collaborator

@thomasferrandiz thomasferrandiz commented Mar 25, 2026

Pin GH Actions to commit sha

This help mitigates supply-chain attack like this one: https://www.stepsecurity.io/blog/trivy-compromised-a-second-time---malicious-v0-69-4-release

@gemini-code-assist
Copy link
Copy Markdown

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

@coveralls
Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 23537023800

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 39.095%

Totals Coverage Status
Change from base Build 23535903332: 0.0%
Covered Lines: 1443
Relevant Lines: 3691

💛 - Coveralls

@thomasferrandiz thomasferrandiz requested review from SchSeba and bpickard22 and removed request for dougbtv March 25, 2026 12:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants