You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We should likely pin Actions used in this repo to specific SHAs with a comment next to them for the version that matches. Dependabot should help keep those updated based on this blog.
Summary
Pulled out from #11 (comment).
We should likely pin Actions used in this repo to specific SHAs with a comment next to them for the version that matches. Dependabot should help keep those updated based on this blog.
I'd also review the security hardening guide for GitHub Actions to ensure we align to best practices.
We may want to validate these changes using OSSF Scorecard.
The text was updated successfully, but these errors were encountered: