You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It is better to pin various actions used across our workflows to their release hash instead of just the version. This helps mitigate concerns around software supply-chain attacks through external workflows. Dependabot can update the version string in a comment and the commit hash when updating the action.
It is better to pin various actions used across our workflows to their release hash instead of just the version. This helps mitigate concerns around software supply-chain attacks through external workflows. Dependabot can update the version string in a comment and the commit hash when updating the action.
If someone wants to do this: this can be done manually, but there are some tools that can do this in an automated manner that might work too: https://stacklok.com/blog/introducing-frizbee-an-open-source-command-line-utility-to-simplify-securing-github-actions
Stemmed off from #4411 (comment).
The text was updated successfully, but these errors were encountered: