Skip to content

ci: pin actions to full commit SHAs#1800

Open
eepifanova wants to merge 2 commits intomainfrom
pin-actions
Open

ci: pin actions to full commit SHAs#1800
eepifanova wants to merge 2 commits intomainfrom
pin-actions

Conversation

@eepifanova
Copy link
Copy Markdown
Contributor

Pin action refs from mutable tags to full commit SHAs to prevent supply-chain attacks.

  • actions/upload-artifact: v6.0.0 -> b7c566a7...
  • actions/download-artifact: v7 -> 37930b1c...
  • azure/login: v2 -> a457da9e...
  • actions/labeler: v6 -> 634933ed...

Actions are pinned to the same versions as it was before. No behaviour changes

Pin action refs from mutable tags to full commit SHAs to prevent
supply-chain attacks.

- actions/upload-artifact: v6.0.0 -> b7c566a7...
- actions/download-artifact: v7 -> 37930b1c...
- azure/login: v2 -> a457da9e...
- actions/labeler: v6 -> 634933ed...

Co-authored-by: Copilot <[email protected]>
@eepifanova eepifanova requested a review from a team as a code owner March 26, 2026 11:35
@github-actions github-actions bot added the tooling Back end, repository, Hugo, and all things not related to content label Mar 26, 2026
@github-actions
Copy link
Copy Markdown

Deploy Preview will be available once build job completes!

Name Link
😎 Deploy Preview https://frontdoor-test-docs.nginx.com/previews/docs/1800/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tooling Back end, repository, Hugo, and all things not related to content

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants