You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is your feature request related to a problem? Please describe.
It's unsafe to reference refs, it's safer to references SHAs, especially if we provide Secrets or other sensitive information.
Vadorequest
changed the title
Reference SHAs instead of refs for external actions
Reference SHAs instead of refs for external GitHub Actions in ".workflows"
Jan 9, 2023
Is your feature request related to a problem? Please describe.
It's unsafe to reference refs, it's safer to references SHAs, especially if we provide Secrets or other sensitive information.
Describe the solution you'd like
We might use something like https://github.com/mheap/pin-github-action and have scripts that run it against our workflows files. And automate it somehow, so that it is enforced.
Describe alternatives you've considered
Doing it manually. Not great DX.
Additional context
https://michaelheap.com/improve-your-github-actions-security/
The text was updated successfully, but these errors were encountered: