Skip to content

ci: pin GitHub Actions to commit SHAs for supply chain security#162

Merged
mmorris35 merged 2 commits intomainfrom
ci/pin-actions-sha
Mar 25, 2026
Merged

ci: pin GitHub Actions to commit SHAs for supply chain security#162
mmorris35 merged 2 commits intomainfrom
ci/pin-actions-sha

Conversation

@mmorris35
Copy link
Copy Markdown
Owner

Summary

  • Pin all GitHub Actions in workflow files to full commit SHAs instead of mutable tags
  • Affects deploy.yml (actions/checkout, actions/setup-node, cloudflare/wrangler-action) and reference-repo-updated.yml (actions/checkout, actions/github-script)
  • Prevents supply chain attacks where a compromised tag could inject malicious code

Changes

Action Old Ref New Ref
actions/checkout @v4 @34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
actions/setup-node @v4 @49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
cloudflare/wrangler-action @v3 @da0e0dfe58b7a431659754fdf3f186c529afbe65 # v3
actions/github-script @v7 @f28e40c7f34bde8b3046d885e986cb6290c5673b # v7

@mmorris35 mmorris35 merged commit eecc17d into main Mar 25, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant