Skip to content

ci: pin GitHub Actions to commit SHAs#409

Open
nicklasl wants to merge 1 commit into
mainfrom
session/reckless-goose-co0m
Open

ci: pin GitHub Actions to commit SHAs#409
nicklasl wants to merge 1 commit into
mainfrom
session/reckless-goose-co0m

Conversation

@nicklasl
Copy link
Copy Markdown
Member

Summary

  • Pin all GitHub Actions to immutable commit SHAs to mitigate supply chain attacks (e.g. TanStack "Mini Shai-Hulud")

Test plan

  • CI passes with SHA-pinned actions

🤖 Generated with Claude Code

Mitigate supply chain attacks (e.g. TanStack "Mini Shai-Hulud")
by pinning all third-party actions to immutable commit SHAs.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@nicklasl nicklasl marked this pull request as ready for review May 20, 2026 11:14
@nicklasl nicklasl changed the title fix(ci): pin GitHub Actions to commit SHAs ci: pin GitHub Actions to commit SHAs May 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant