Skip to content

Pin GitHub Actions to immutable commit SHAs #15

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 3 commits into from
Apr 2, 2025

Conversation

roryabraham
Copy link
Contributor

Coming from https://expensify.slack.com/archives/CC7NECV4L/p1743022578963949, this pull request updates all mutable action references to use immutable commit hashes instead. This is a security measure to protect from supply chain attacks.

Copy link

github-actions bot commented Mar 31, 2025

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@roryabraham roryabraham self-assigned this Apr 1, 2025
@roryabraham roryabraham requested a review from a team April 1, 2025 01:35
@melvin-bot melvin-bot bot requested review from chiragsalian and removed request for a team April 1, 2025 01:35
chiragsalian
chiragsalian previously approved these changes Apr 1, 2025
@chiragsalian
Copy link
Contributor

You have to sign CLA.

@roryabraham
Copy link
Contributor Author

I have read the CLA Document and I hereby sign the CLA

@chiragsalian
Copy link
Contributor

sorry, now you've got conflicts to resolve.

@roryabraham
Copy link
Contributor Author

@chiragsalian conflicts resolved

@roryabraham roryabraham requested a review from chiragsalian April 2, 2025 22:21
@chiragsalian chiragsalian merged commit 18b4222 into main Apr 2, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants