Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pin GitHub actions by hash #14

Merged
merged 1 commit into from
Jun 5, 2024
Merged

Pin GitHub actions by hash #14

merged 1 commit into from
Jun 5, 2024

Conversation

joaander
Copy link
Member

@joaander joaander commented Jun 5, 2024

Description

Follow security recommendations and pin all GitHub actions by hash.
Also make use of reusable workflows and actions.

Motivation and context

  • Ensure that rewritten tags on upstream repositories cannot be used to execute arbitrary code in our CI.
  • Reduce the amount of code duplication between projects. Provide a single place to update tools to the latest version.

How has this been tested?

CI checks.

Checklist:

  • I have reviewed the Contributor Guidelines.
  • I agree with the terms of the Row Contributor Agreement.
  • My name is on the list of contributors (doc/src/contributors.md) in the pull request source branch.
  • I have added a change log entry to doc/src/release-notes.md.

Also make use of reusable workflows and actions.
@joaander joaander merged commit 2a0e721 into trunk Jun 5, 2024
17 checks passed
@joaander joaander deleted the harden-ci branch June 5, 2024 15:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant