Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pinned versions for GitHub actions #2821

Merged
merged 5 commits into from
Dec 18, 2023
Merged

Conversation

flo-dup
Copy link
Contributor

@flo-dup flo-dup commented Dec 5, 2023

Please check if the PR fulfills these requirements

  • The commit message follows our guidelines

Does this PR already have an issue describing the problem?
No, but score of Pinned-dependencies highlights the problem

What kind of change does this PR introduce?
Security fix

What is the current behavior?
Version not pinned for github actions: attacker might change the tag.

What is the new behavior (if this is a feature change)?
Version pinned for github actions

Does this PR introduce a breaking change or deprecate an API?

  • Yes
  • No

Sorry, something went wrong.

Signed-off-by: Florian Dupuy <florian.dupuy@rte-france.com>
Signed-off-by: Florian Dupuy <florian.dupuy@rte-france.com>
@flo-dup flo-dup requested a review from olperr1 December 5, 2023 14:24

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature. The key has expired.

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature. The key has expired.

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature. The key has expired.
Copy link

Quality Gate Passed Quality Gate passed

Kudos, no new issues were introduced!

0 New issues
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarCloud

@annetill annetill merged commit 3c391da into main Dec 18, 2023
6 checks passed
@annetill annetill deleted the pinned_version_github_action branch December 18, 2023 10:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants