Commit cc713c0
ci: SHA-pin GitHub Actions for supply-chain security (#146)
* build: SHA-pin GitHub Actions for supply-chain security
Pin external action references to exact commit SHAs instead of
branch or major-version tags to prevent supply-chain attacks.
Signed-off-by: jimisola <jimisola@jimisola.com>
* ci: potential fix for code scanning alert no. 10: Workflow does not contain permissions
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Jimisola Laursen <jimisola@jimisola.com>
---------
Signed-off-by: jimisola <jimisola@jimisola.com>
Signed-off-by: Jimisola Laursen <jimisola@jimisola.com>
Co-authored-by: Jimisola Laursen <jimisola.laursen@resurs.se>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>1 parent dd4a737 commit cc713c0
1 file changed
+4
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
8 | 11 | | |
9 | 12 | | |
10 | | - | |
| 13 | + | |
0 commit comments