Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build: Pin GitHub Actions to SHA. #2736

Merged
merged 1 commit into from
Sep 17, 2021

Conversation

naveensrinivasan
Copy link
Contributor

@naveensrinivasan naveensrinivasan commented Sep 6, 2021

@naveensrinivasan
Copy link
Contributor Author

If dependabot is enabled it will provide an option to upgrade these actions.

.github/workflows/go.yml Outdated Show resolved Hide resolved
@davecgh davecgh changed the title Pinned GitHub Actions to SHA build: Pin GitHub Actions to SHA. Sep 7, 2021
@davecgh davecgh added the waiting for changes Pull requests that are waiting for changes from the submitter. label Sep 17, 2021
* The actions tags can be moved. So pinned the actions based on SHA.
 https://julienrenaux.fr/2019/12/20/github-actions-security-risk/
@naveensrinivasan naveensrinivasan force-pushed the naveen/feat/actions-pinning branch from f6919c7 to b7baa43 Compare September 17, 2021 14:46
@davecgh davecgh merged commit e22b4e4 into decred:master Sep 17, 2021
@davecgh davecgh removed the waiting for changes Pull requests that are waiting for changes from the submitter. label Sep 17, 2021
@davecgh davecgh added this to the 1.7.0 milestone Sep 17, 2021
@naveensrinivasan naveensrinivasan deleted the naveen/feat/actions-pinning branch September 17, 2021 16:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants