Skip to content

Pin GitHub Actions to commit SHAs for supply chain security#33

Closed
jzyinq wants to merge 1 commit intomasterfrom
feature/ARCH-884-github-action-sha-pin
Closed

Pin GitHub Actions to commit SHAs for supply chain security#33
jzyinq wants to merge 1 commit intomasterfrom
feature/ARCH-884-github-action-sha-pin

Conversation

@jzyinq
Copy link
Contributor

@jzyinq jzyinq commented Jan 30, 2026

Summary

Pin external GitHub Actions from tags to commit SHAs for supply chain security.

Changes

Replace tag references with full commit SHA hashes.

Affected actions:

  • actions/checkout@v2
  • actions/setup-python@v2
  • actions/setup-python@v4

@jzyinq jzyinq requested a review from a team as a code owner January 30, 2026 09:00
@jzyinq
Copy link
Contributor Author

jzyinq commented Feb 3, 2026

Closing, as affected actions are considered to be safe using tags according to this policy.

@jzyinq jzyinq closed this Feb 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant