Skip to content

fix(ci): 3rd party Github Actions should be pinned - #1165

Merged
triceo merged 1 commit into
developmentfrom
fix/aikido-security-sast-94018686-p4na
Aug 21, 2026
Merged

fix(ci): 3rd party Github Actions should be pinned#1165
triceo merged 1 commit into
developmentfrom
fix/aikido-security-sast-94018686-p4na

Conversation

@aikido-autofix

Copy link
Copy Markdown
Contributor

Description of the change

This patch mitigates a potential supply chain attack by pinning the version of third-party Github Actions to their commit SHA.

Checklist

Development

  • The changes have been covered with tests, if necessary.
  • You have a green build, with the exception of the flaky tests.
  • UI and JS files are fully tested, the user interface works for all modules affected by your changes (e.g., solve and analyze buttons).
  • The network calls work for all modules affected by your changes (e.g., solving a problem).
  • The console messages are validated for all modules affected by your changes.

Code Review

  • This pull request includes an explanatory title and description.
  • The GitHub issue is linked.
  • At least one other engineer has approved the changes.
  • After PR is merged, inform the reporter.

Related Tasks & Ticket Links:

AI Confidence Level: High confidence: Aikido has a robust set of benchmarks for similar fixes, and they are proven to be effective.

@triceo triceo changed the title [Aikido] AI Fix for 3rd party Github Actions should be pinned fix(ci): 3rd party Github Actions should be pinned Aug 21, 2026
@triceo
triceo merged commit aafb6e3 into development Aug 21, 2026
45 checks passed
@triceo
triceo deleted the fix/aikido-security-sast-94018686-p4na branch August 21, 2026 09:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant