Skip to content

chore: update action pinning hash commit in github workflows#43

Open
ddevsr wants to merge 15 commits into
codeigniter4:mainfrom
ddevsr:patch-2
Open

chore: update action pinning hash commit in github workflows#43
ddevsr wants to merge 15 commits into
codeigniter4:mainfrom
ddevsr:patch-2

Conversation

@ddevsr
Copy link
Copy Markdown

@ddevsr ddevsr commented Jun 4, 2026

Description
This PR pins GitHub Actions from mutable version tags (e.g. action/checkout@v5) to full commit SHAs, preventing silent supply chain attacks from compromised action repositories.

Recommended by GitHub's security hardening guide

Checklist:

  • Securely signed commits
  • Component(s) with PHPDoc blocks, only if necessary or adds value
  • Unit testing, with >80% coverage
  • User guide updated
  • Conforms to style guide

@ddevsr
Copy link
Copy Markdown
Author

ddevsr commented Jun 4, 2026

@paulbalandan @michalsn needed approve on this

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants