Skip to content

chore: pin GitHub Actions to commit SHAs#60

Merged
jinhyoo-mp merged 2 commits into
masterfrom
pin-actions-to-sha
May 5, 2026
Merged

chore: pin GitHub Actions to commit SHAs#60
jinhyoo-mp merged 2 commits into
masterfrom
pin-actions-to-sha

Conversation

@austinpray-mixpanel
Copy link
Copy Markdown
Member

@austinpray-mixpanel austinpray-mixpanel commented Mar 24, 2026

Summary

Pin all GitHub Actions workflow steps to immutable full commit SHAs instead of mutable tags or branches.

Why

Mutable tags can be moved after the fact, making it possible for a supply-chain attack to inject malicious code into CI. Pinning to a commit SHA ensures the exact version of an action is used, and the original tag is preserved as an inline comment for readability.

Verification

Review the diff — all uses: lines with third-party actions should now reference a 40-character commit SHA with the original tag as an inline comment.

🤖 Generated with Claude Code

Linear: https://linear.app/mixpanel/issue/DEV-72/pin-all-github-actions-to-commit-shas

@austinpray-mixpanel austinpray-mixpanel requested review from a team, ebracho, krishna16v and tylerjroach and removed request for a team March 24, 2026 03:46
@austinpray-mixpanel austinpray-mixpanel changed the title chore: pin GitHub Actions to commit SHAs [DEV-72] chore: pin GitHub Actions to commit SHAs Mar 24, 2026
@linear
Copy link
Copy Markdown

linear Bot commented Mar 24, 2026

@gmasnica gmasnica self-requested a review March 24, 2026 23:11
# Conflicts:
#	.github/workflows/ci.yml
#	.github/workflows/release.yml
@jinhyoo-mp jinhyoo-mp changed the title [DEV-72] chore: pin GitHub Actions to commit SHAs chore: pin GitHub Actions to commit SHAs May 5, 2026
@jinhyoo-mp jinhyoo-mp merged commit 164d281 into master May 5, 2026
14 of 16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants