Skip to content

ci: pin GitHub Actions dependencies to commit hashes#61

Open
Siddhant-K-code wants to merge 1 commit intogoogle:mainfrom
Siddhant-K-code:ci/use-pinned-dependencies
Open

ci: pin GitHub Actions dependencies to commit hashes#61
Siddhant-K-code wants to merge 1 commit intogoogle:mainfrom
Siddhant-K-code:ci/use-pinned-dependencies

Conversation

@Siddhant-K-code
Copy link
Contributor

This hardening is critical following multiple GitHub Actions supply chain attacks in March 2025, including the compromise of popular actions like tj-actions/changed-files (CVE-2025-30066) and reviewdog/action-setup (CVE-2025-30154). Pinning to commit hashes prevents dependency confusion attacks and ensures reproducible builds by preventing automatic updates to potentially compromised versions.

@gemini-code-assist
Copy link
Contributor

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant