You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It's awesome that secure repo pins dependencies like GHA. However, it is ideal to keep that hygiene to ensure new dependencies that are introduced must be pinned (bonus points if it can suggest hashes). It would be great to add an action like https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions as part of secure repo or harden runner.
If this issue is more suitable for harden-repo repo, please feel free to move it there.
The text was updated successfully, but these errors were encountered:
@sozercan, please do suggest if you have ideas on adding additional tools via pull request using secure-repo. Here are some we are planning to do in the near future: #2069 #2074 #2076
It's awesome that secure repo pins dependencies like GHA. However, it is ideal to keep that hygiene to ensure new dependencies that are introduced must be pinned (bonus points if it can suggest hashes). It would be great to add an action like https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions as part of secure repo or harden runner.
If this issue is more suitable for
harden-repo
repo, please feel free to move it there.The text was updated successfully, but these errors were encountered: