Skip to content

feat: pin GitHub Actions versions to a full length commit SHA#103

Closed
jhult wants to merge 1 commit intoFiorenMas:mainfrom
jhult:feat/pin-gha-sha
Closed

feat: pin GitHub Actions versions to a full length commit SHA#103
jhult wants to merge 1 commit intoFiorenMas:mainfrom
jhult:feat/pin-gha-sha

Conversation

@jhult
Copy link
Copy Markdown
Contributor

@jhult jhult commented Jan 5, 2026

Ran these 2:

pinact run --update
zizmor --persona auditor --gh-token $(gh auth token) --fix=all .github/workflows/*.yml


https://github.com/suzuki-shunsuke/pinact#motivation
https://docs.github.com/en/actions/reference/security/secure-use#using-third-party-actions

image

pinact run --update
zizmor --persona auditor --gh-token $(gh auth token) --fix=all .github/workflows/*.yml
@FiorenMas FiorenMas closed this Jan 10, 2026
@jhult jhult deleted the feat/pin-gha-sha branch February 14, 2026 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants