Skip to content

Revert worsened workflow security #27

@llucax

Description

@llucax

What happened?

PR #17 accidentally reverted a lot of security enhancements in GitHub workflows, which leaves this project more vulnerable to attacks.

What did you expect instead?

Workflows to be only updated with necessary changes, and this new changes to have the same security hardening as the existing workflow code (like pinning actions using hashes).

Affected version(s)

No response

Affected part(s)

Build script, CI, dependencies, etc. (part:tooling)

Extra information

More context in the PR #17.

Metadata

Metadata

Labels

priority:highAddress this as soon as possibletype:bugSomething isn't working
No fields configured for Regression.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions