Replace floating tag refs (@v1, @v2) with SHA-pinned refs to prevent supply-chain attacks via tag mutation on third-party Actions. Pinned: - useblacksmith/setup-docker-builder@v1 → ef12d5b1 - useblacksmith/build-push-action@v2 → 30c71162 Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| auto-response.yml | ||
| ci.yml | ||
| codeql.yml | ||
| docker.yml | ||
| labeler.yml | ||
| pr-hygiene.yml | ||
| release.yml | ||
| security.yml | ||
| stale.yml | ||
| update-notice.yml | ||
| workflow-sanity.yml | ||