Skip to content

ci: pin GitHub Actions to SHAs for security#12972

Open
janiussyafiq wants to merge 1 commit intoapache:masterfrom
janiussyafiq:task/pin-ga-shas
Open

ci: pin GitHub Actions to SHAs for security#12972
janiussyafiq wants to merge 1 commit intoapache:masterfrom
janiussyafiq:task/pin-ga-shas

Conversation

@janiussyafiq
Copy link
Contributor

Description

This PR transitions third-party GitHub Actions from mutable tags (e.g., @v3 or @master to full-length, immutable commit SHAs for better security

Which issue(s) this PR fixes:

Fixes #12938

Checklist

  • I have explained the need for this PR and the problem it solves
  • I have explained the changes or the new features added to this PR
  • I have added tests corresponding to this change
  • I have updated the documentation to reflect this change
  • I have verified that this change is backward compatible (If not, please discuss on the APISIX mailing list first)

@dosubot dosubot bot added size:M This PR changes 30-99 lines, ignoring generated files. github_actions Pull requests that update GitHub Actions code labels Feb 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github_actions Pull requests that update GitHub Actions code size:M This PR changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: github actions version pinning

3 participants