Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

πŸ”’οΈ Pinned all 3rd party actions to latest release commit hashes #481

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

KemingHe
Copy link
Collaborator

@KemingHe KemingHe commented Jan 5, 2025

Using broad versions (i.e. v4) rather than specific commit hashes makes the workflow vulnerable to supply chain attacks. This is considered a medium level security risk by GitHub CodeQL and is reported and explain in #480.

This PR fixes #480 .

using broad versions i.e. v4 rather than specific commit hashes makes the workflow vulnerable to supply chain attacks
Copy link

changeset-bot bot commented Jan 5, 2025

πŸ¦‹ Changeset detected

Latest commit: de5b8d7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
socialify Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Copy link

netlify bot commented Jan 5, 2025

βœ… Deploy Preview for github-socialify ready!

Name Link
πŸ”¨ Latest commit de5b8d7
πŸ” Latest deploy log https://app.netlify.com/sites/github-socialify/deploys/6779d17edcdb6a0008e643c6
😎 Deploy Preview https://deploy-preview-481--github-socialify.netlify.app
πŸ“± Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
1 participant