Pin every third-party GitHub Action to its current commit SHA with a version comment, eliminating supply chain risk from mutable version tags. Mutable tags (v4, v2, etc.) can be force-pushed by upstream maintainers; SHA digests are immutable. 18 unique actions pinned across 9 workflow files. Closes #357 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| auto-response.yml | ||
| ci.yml | ||
| docker.yml | ||
| labeler.yml | ||
| pr-hygiene.yml | ||
| release.yml | ||
| security.yml | ||
| stale.yml | ||
| workflow-sanity.yml | ||