Skip to content

Pin third-party actions to commit SHAs#3

Merged
ahosgood merged 4 commits into
mainfrom
pinact/pin-actions
Apr 27, 2026
Merged

Pin third-party actions to commit SHAs#3
ahosgood merged 4 commits into
mainfrom
pinact/pin-actions

Conversation

@kurtismash

Copy link
Copy Markdown
Member

This PR pins third-party GitHub Actions to full commit SHAs for supply-chain security.

This has been done automatically by pinact. When reviewing please confirm that the SHAs are correct, zizmor will alert if not.

As a maintainer, please merge this PR once approved.

@ahosgood ahosgood self-assigned this Apr 24, 2026
@wiz-2986343e2e

wiz-2986343e2e Bot commented Apr 27, 2026

Copy link
Copy Markdown

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities -
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total -

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

Pull Request Developer Guidance

If the link to the Wiz scan details doesn't work, please ensure you are using the right role in Wiz and that the repository is assigned to the correct project within our Wiz Terraform. Or, you can ask for help in #tna-cloud-security on Slack.

Comment thread .github/workflows/cd.yml
Comment thread .github/workflows/cd.yml
@ahosgood ahosgood merged commit 0ff5b1f into main Apr 27, 2026
19 checks passed
@ahosgood ahosgood deleted the pinact/pin-actions branch April 27, 2026 10:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants