Skip to content
This repository was archived by the owner on Mar 26, 2026. It is now read-only.

chore: [SEC-7924] pin third-party GitHub Actions to commit SHAs#31

Closed
pkaeding wants to merge 1 commit intomainfrom
security/SEC-7924/pin-github-actions
Closed

chore: [SEC-7924] pin third-party GitHub Actions to commit SHAs#31
pkaeding wants to merge 1 commit intomainfrom
security/SEC-7924/pin-github-actions

Conversation

@pkaeding
Copy link
Copy Markdown

@pkaeding pkaeding commented Mar 23, 2026

Summary

Pin all third-party GitHub Actions to full-length commit SHAs to prevent supply chain attacks.

Addresses findings from the third-party-action-not-pinned-to-commit-sha Semgrep rule.

Test plan

  • Verify CI passes with pinned action SHAs

Related Jira issue: SEC-7924: Unpinned GitHub Actions remediation

Pin all third-party GitHub Actions to full-length commit SHAs to prevent
supply chain attacks. Addresses findings from the
third-party-action-not-pinned-to-commit-sha Semgrep rule.
@launchdarkly-upra launchdarkly-upra Bot changed the title chore: pin third-party GitHub Actions to commit SHAs chore: [SEC-7924] pin third-party GitHub Actions to commit SHAs Mar 23, 2026
@pkaeding pkaeding requested review from a team March 25, 2026 13:41
@pkaeding pkaeding closed this Mar 26, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant