Commit 50852c8
authored
fix(ci): pin guardrail actions to SHAs and guard body-file usage (#19232)
Pin actions/checkout and actions/github-script to immutable commit SHAs
in scanner-merge-guardrails.yml to prevent supply-chain attacks via tag
force-push.
Guard --body-file usage in kb-nightly-validation.yml to handle cases
where kb-gap-report.md is not generated.
Fixes #18643, Fixes #19072
Signed-off-by: Andrew Anderson <andy@clubanderson.com>1 parent f2865b9 commit 50852c8
2 files changed
Lines changed: 13 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
127 | 127 | | |
128 | 128 | | |
129 | 129 | | |
130 | | - | |
131 | | - | |
132 | | - | |
133 | | - | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
134 | 141 | | |
135 | 142 | | |
136 | 143 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| 24 | + | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
28 | | - | |
| 28 | + | |
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
| |||
0 commit comments